Skip to main content

SessionCredentialIssuer

Trait SessionCredentialIssuer 

Source
pub trait SessionCredentialIssuer: Send + Sync {
    // Required methods
    fn issue(
        &self,
        role_arn: &str,
        session_name: &str,
        duration: Duration,
    ) -> SessionCredentials;
    fn revoke(&self, credentials: &SessionCredentials);
}
Expand description

Issues assumed-role session credentials on behalf of a compute service, registered so that requests signed with them resolve to arn:<partition>:sts::<account>:assumed-role/<role>/<session> (and verify under --verify-sigv4). Implemented over IAM state; services that run user code under a role take it as an optional hook so they stay decoupled from the IAM crate.

Required Methods§

Source

fn issue( &self, role_arn: &str, session_name: &str, duration: Duration, ) -> SessionCredentials

Mint credentials for role_arn with the given session name, valid for duration.

Source

fn revoke(&self, credentials: &SessionCredentials)

Unregister credentials once the code they were issued to has stopped. Idempotent.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§