Skip to content

fix(services/oss): prefer OIDC credentials over ECS metadata - #8339

Merged
Xuanwo merged 1 commit into
apache:mainfrom
WenyXu:fix/oss-oidc-before-metadata
Sep 23, 2026
Merged

Xuanwo merged 1 commit into
apache:mainfrom
WenyXu:fix/oss-oidc-before-metadata

Conversation

@WenyXu

@WenyXu WenyXu commented Sep 23, 2026

Copy link
Copy Markdown
Member

Which issue does this PR close?

Closes #8338. Related to #7480.

Rationale for this change

Adding ECS RAM role credentials in #7480 placed instance metadata before OIDC in the OSS credential chain. On ACK, a pod with RRSA configured can therefore use the node role instead of its configured OIDC role when both credential sources are available. Loading credentials succeeds, but OSS can reject the subsequent write because the node role lacks permission.

The reporter observed this against actual Aliyun OSS after upgrading GreptimeDB from v1.0.2 (OpenDAL 0.54.1) to v1.1.0 (OpenDAL 0.57.0), with the same RRSA configuration. CREATE TABLE failed with HTTP 403 while writing the manifest. The reporter confirmed that setting ALIBABA_CLOUD_ECS_METADATA_DISABLED=true and restarting restored operation.

What changes are included in this PR?

  • Resolve credentials in this order: explicit access keys, environment credentials, OIDC, then ECS instance metadata.
  • Exercise the backend's actual signer with isolated environment, file, and HTTP providers. Check the selected key, security token, and credential requests for all four precedence cases, including OIDC and ECS both being available.
  • Document credential precedence and fallback behavior.

Validation: OSS crate tests (9 unit tests and 2 doc tests). With identical test inputs, reverting only the provider order fails the regression test in both runs; the fixed order passes both runs. cargo clippy -p opendal-service-oss --all-targets --locked -- -D warnings and cargo fmt --all -- --check passed.

The patched build has not yet been tested against live OSS. The service evidence above is the reporter's upgrade/workaround comparison; the local test establishes credential selection and signing behavior.

Are there any user-facing changes?

Yes. When both OIDC and ECS instance credentials are available, OSS uses OIDC first. Explicit and environment access keys retain their precedence. ECS remains available when preceding providers return no credentials or fail. An OSS 403 does not trigger a switch to another identity.

Breaking changes

AI Usage Statement

  • Harness: Codex.
  • Model: GPT-6.
  • Effort: Not exposed in this session.
  • Role: Assisted with dependency and upstream-change analysis, implementation, regression tests, validation, and this description. Actual-service reproduction and workaround confirmation were supplied by the human reporter; AI validation used isolated credential responses.

Signed-off-by: WenyXu <wenymedia@gmail.com>
@github-actions github-actions Bot added releases-note/fix The PR fixes a bug or has a title that begins with "fix" services/oss size:L This PR changes 100-499 lines, ignoring generated files. labels Sep 23, 2026
@WenyXu
WenyXu marked this pull request as ready for review September 23, 2026 03:28
@WenyXu
WenyXu requested a review from Xuanwo as a code owner September 23, 2026 03:28
Copilot AI lite review requested due to automatic review settings September 23, 2026 03:28

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Xuanwo
Xuanwo merged commit 8eb647c into apache:main Sep 23, 2026
118 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

releases-note/fix The PR fixes a bug or has a title that begins with "fix" services/oss size:L This PR changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(services/oss): ECS metadata credentials take precedence over ACK RRSA

3 participants