如果找不到环境变量,如何从文件回退到凭据?

问题描述 投票:0回答:1

如果未找到环境变量,我如何回退以使用已解析文件(config.yml)中的凭据?为了进行测试,我使用的是this example

extern crate rusoto_core;
extern crate rusoto_s3;

use rusoto_core::credential::ChainProvider;
use rusoto_core::request::HttpClient;
use rusoto_core::Region;
use rusoto_s3::{S3, S3Client};
use std::time::{Duration, Instant};

fn main() {
    let mut chain = ChainProvider::new();
    chain.set_timeout(Duration::from_millis(200));
    let s3client = S3Client::new_with(
        HttpClient::new().expect("failed to create request dispatcher"),
        chain,
        Region::UsEast1,
    );

    let start = Instant::now();
    println!("Starting up at {:?}", start);

    match s3client.list_buckets().sync() {
        Err(e) => println!("Error listing buckets: {}", e),
        Ok(buckets) => println!("Buckets found: {:?}", buckets),
    };
    println!("Took {:?}", Instant::now().duration_since(start));
}

它可以工作,但是需要环境变量AWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEY。我想对其进行扩展,以便在没有定义的环境变量的情况下,可以使用在已解析文件中找到的键:

// parse config file
let file = std::fs::File::open("config.yml").expect("Unable to open file");
let yml: Config = match serde_yaml::from_reader(file) {
    Err(err) => {
        println!("Error: {}", err);
        return;
    }
    Ok(yml) => yml,
};

例如config.yml可能类似于:

---
endpoint: s3.provider
access_key: ACCESS_KEY_ID
secret_key: SECRET_ACCESS_KEY

我可以添加到chain以使用在config.yml中找到的凭据,可能类似于:

let config_provider = StaticProvider::new_minimal(yml.access_key, yml.secret_key);

如何优先考虑环境,如果找不到,则使用StaticProvider提供的凭据?

amazon-s3 rust rusoto
1个回答
1
投票

ChainProvider实际上具有four sources来检查AWS凭证。第三个是位于用户主目录中的AWS配置文件。但其格式是预定的。

如果您坚持使用自己的YAML文件,则可以像这样将EnvironmentProviderStaticProvider链接在一起:

use futures::future::Future;
use rusoto_core::request::HttpClient;
use rusoto_core::Region;
use rusoto_credential::{
    AwsCredentials,
    CredentialsError,
    EnvironmentProvider,
    ProvideAwsCredentials,
    StaticProvider,
};
use rusoto_s3::{S3, S3Client};
use std::time::Instant;

struct MyChainProvider {
    access_key: String,
    secret_key: String, 
}

impl ProvideAwsCredentials for MyChainProvider {
    type Future = Box<dyn Future<Item=AwsCredentials, Error=CredentialsError> + Send>;

    fn credentials(&self) -> Self::Future {
        let access_key = self.access_key.clone();
        let secret_key = self.secret_key.clone();
        let future = EnvironmentProvider::default().credentials()
            .or_else(move |_| -> Self::Future {
                Box::new(StaticProvider::new_minimal(access_key, secret_key).credentials())
            });

        Box::new(future)
    }
}

fn main() {
    let chain = MyChainProvider {
        access_key: ...,
        secret_key: ...,
    };
    let s3client = S3Client::new_with(
        HttpClient::new().expect("failed to create request dispatcher"),
        chain,
        Region::UsEast1,
    );

    ...
}
© www.soinside.com 2019 - 2024. All rights reserved.