
AWS EksToken
CertifiedGenerate a presigned EKS authentication token
AWS EksToken
Generate a presigned EKS authentication token
Builds a short-lived k8s-aws-v1 token for a given EKS cluster by presigning STS GetCallerIdentity. Requires region and cluster name; expirationDuration defaults to 600s.
type: io.kestra.plugin.aws.auth.EksTokenExamples
id: aws_eks_oauth_token
namespace: company.team
tasks:
- id: get_eks_token
type: io.kestra.plugin.aws.auth.EksToken
accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
region: "eu-central-1"
clusterName: "my-cluster"
Properties
clusterName *Requiredstring
EKS cluster name
Cluster identifier passed in x-k8s-aws-id when presigning.
accessKeyId string
Access Key Id in order to connect to AWS
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
compatibilityMode booleanstring
Enable compatibility mode
Use it to connect to S3 bucket with S3 compatible services that don't support the new transport client.
endpointOverride string
The endpoint with which the SDK should communicate
This property allows you to use a different S3 compatible storage backend.
expirationDuration integerstring
600Token TTL (seconds)
Lifetime of the presigned URL; default 600 seconds.
forcePathStyle booleanstring
Force path style access
Must only be used when compatibilityMode is enabled.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
region string
AWS region with which the SDK should communicate
secretKeyId string
Secret Key Id in order to connect to AWS
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
sessionToken string
AWS session token, retrieved from an AWS token service, used for authenticating that this user has received temporary permissions to access a given resource
If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
stsEndpointOverride string
The AWS STS endpoint with which the SDKClient should communicate
stsRoleArn string
AWS STS Role
The Amazon Resource Name (ARN) of the role to assume. If set the task will use the StsAssumeRoleCredentialsProvider. If no credentials are defined, we will use the default credentials provider chain to fetch credentials.
stsRoleExternalId string
AWS STS External Id
A unique identifier that might be required when you assume a role in another account. This property is only used when an stsRoleArn is defined.
stsRoleSessionDuration string
PT15MAWS STS Session duration
The duration of the role session (default: 15 minutes, i.e., PT15M). This property is only used when an stsRoleArn is defined.
stsRoleSessionName string
AWS STS Session name
This property is only used when an stsRoleArn is defined.
Outputs
token *Required
EKS auth token
Bearer token formatted as k8s-aws-v1.
io.kestra.plugin.aws.auth.EksToken-Token
date-timeToken expiration time
Exact UTC expiration timestamp derived from the provided TTL.
OAuth access token value
Will be automatically encrypted and decrypted in the outputs if encryption is configured