AWS EksToken

AWS EksToken

Certified

Generate a presigned EKS authentication token

Builds a short-lived k8s-aws-v1 token for a given EKS cluster by presigning STS GetCallerIdentity. Requires region and cluster name; expirationDuration defaults to 600s.

yaml
type: io.kestra.plugin.aws.auth.EksToken
yaml
id: aws_eks_oauth_token
namespace: company.team

tasks:
  - id: get_eks_token
    type: io.kestra.plugin.aws.auth.EksToken
    accessKeyId: "{{ secret('AWS_ACCESS_KEY_ID') }}"
    secretKeyId: "{{ secret('AWS_SECRET_KEY_ID') }}"
    region: "eu-central-1"
    clusterName: "my-cluster"
Properties

EKS cluster name

Cluster identifier passed in x-k8s-aws-id when presigning.

Access Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

Enable compatibility mode

Use it to connect to S3 bucket with S3 compatible services that don't support the new transport client.

The endpoint with which the SDK should communicate

This property allows you to use a different S3 compatible storage backend.

Default600

Token TTL (seconds)

Lifetime of the presigned URL; default 600 seconds.

Force path style access

Must only be used when compatibilityMode is enabled.

Reference (ref) of the pluginDefaults to apply to this task.

AWS region with which the SDK should communicate

Secret Key Id in order to connect to AWS

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS session token, retrieved from an AWS token service, used for authenticating that this user has received temporary permissions to access a given resource

If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

The AWS STS endpoint with which the SDKClient should communicate

AWS STS Role

The Amazon Resource Name (ARN) of the role to assume. If set the task will use the StsAssumeRoleCredentialsProvider. If no credentials are defined, we will use the default credentials provider chain to fetch credentials.

AWS STS External Id

A unique identifier that might be required when you assume a role in another account. This property is only used when an stsRoleArn is defined.

DefaultPT15M

AWS STS Session duration

The duration of the role session (default: 15 minutes, i.e., PT15M). This property is only used when an stsRoleArn is defined.

AWS STS Session name

This property is only used when an stsRoleArn is defined.

EKS auth token

Bearer token formatted as k8s-aws-v1.; encrypted in outputs when supported.

Definitions
expirationTimestring
Formatdate-time

Token expiration time

Exact UTC expiration timestamp derived from the provided TTL.

tokenValuestring

OAuth access token value

Will be automatically encrypted and decrypted in the outputs if encryption is configured