[JIRA] (JENKINS-48096) EC2 plugin does not obtain new credentials based on IAM role each time it launch a new slave instance

12 views
Skip to first unread message

jamieschuts@protonmail.com (JIRA)

unread,
Sep 14, 2018, 1:44:03 AM9/14/18
to jenkinsc...@googlegroups.com
pete barnes commented on Improvement JENKINS-48096
 
Re: EC2 plugin does not obtain new credentials based on IAM role each time it launch a new slave instance

Francis Upton any plans to close out this issue? it's a blocker for us. Only way we can seem to get it to work is to keep saving the credentials manually (which forces a refresh). However it means we can't use it for automation.

Thanks!

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v7.11.2#711002-sha1:fdc329d)

ben.copeland@menlosecurity.com (JIRA)

unread,
Mar 21, 2019, 1:20:02 PM3/21/19
to jenkinsc...@googlegroups.com

This is an issue with us as well. Almost verbatim the same symptoms as described above. I have confirmed with AWS support this is indeed a session timeout. The plugin does not re-auth and refresh the session. Maybe a session refresh interval as a configuration option or something along those lines. 

ben.copeland@menlosecurity.com (JIRA)

unread,
Mar 22, 2019, 2:42:02 PM3/22/19
to jenkinsc...@googlegroups.com

ben.copeland@menlosecurity.com (JIRA)

unread,
Mar 22, 2019, 2:56:02 PM3/22/19
to jenkinsc...@googlegroups.com
Ben Copeland commented on Bug JENKINS-48096
 
Re: EC2 plugin does not obtain new credentials based on IAM role each time it launch a new slave instance

After looking closer this seems to be a bug. Was this not "fixed" with issues like JENKINS-36516 

I confirmed with AWS support after looking through the session logs the session is in fact expiring and the plug-in is failing to refresh. 

ben.copeland@menlosecurity.com (JIRA)

unread,
Mar 22, 2019, 3:00:02 PM3/22/19
to jenkinsc...@googlegroups.com

raihaan.shouhell@autodesk.com (JIRA)

unread,
Jul 31, 2019, 5:26:06 AM7/31/19
to jenkinsc...@googlegroups.com
Raihaan Shouhell resolved as Fixed
 

The session auto refreshes if expired now

Change By: Raihaan Shouhell
Status: Open Resolved
Resolution: Fixed

rsandell@cloudbees.com (JIRA)

unread,
Aug 28, 2019, 12:09:04 PM8/28/19
to jenkinsc...@googlegroups.com
rsandell commented on Bug JENKINS-48096
 
Re: EC2 plugin does not obtain new credentials based on IAM role each time it launch a new slave instance

Any insight into what was fixed in 1.44 that fixed this issue?
I'm investigating if it is possible to backport the fix into the 1.42 line.

raihaan.shouhell@autodesk.com (JIRA)

unread,
Aug 28, 2019, 12:12:03 PM8/28/19
to jenkinsc...@googlegroups.com

This shouldn't be too hard to backport. https://github.com/jenkinsci/ec2-plugin/pull/378 is the current implementation of checking if creds are ok and refreshing them

Reply all
Reply to author
Forward
0 new messages