All Products
Search
Document Center

Identity as a Service:Best practice: obtain STS credentials on ACK without static credentials

Last Updated:Sep 24, 2026

For applications that run on an ACK cluster, obtain temporary STS credentials for a specific RAM role without static credentials, by combining an OIDC token injected through ACK RRSA for federated authentication with PAM authorization.

How it works

An M2M client application that runs in an ACK pod calls the IDaaS SDK. The SDK uses the Kubernetes ServiceAccount OIDC token injected by ACK RRSA to complete federated authentication for the M2M client application. The SDK then uses the resulting token to call PAM and obtain temporary STS credentials for the target cloud role. The application does not need to store a client secret or a long-term AccessKey.

Prerequisites

  • The Machine Identity Management and Privileged Access Management capabilities of IDaaS EIAM are enabled.

  • You have RAM administrative permissions and have identified the least privileges that the target RAM role needs.

  • You have created an ACK managed cluster (version 1.22 or later) and have ACK administrative permissions.

  • The workload pod can reach the public endpoint of the EIAM instance.

References

Configuration steps

Step 1: Add a cloud account and system cloud role in Asset Management

In the IDaaS EIAM console, go to Asset Management > Cloud Identity and add the target Alibaba Cloud account. Follow the console prompts to configure the identity provider, system cloud role, and detection items, and confirm that both the cloud account and the system cloud role are in the Available state.

Step 2: Add the target cloud role that obtains the final STS credentials

In Cloud Role Management for the managed cloud account, add the target RAM role. Confirm that the cloud role is in the Enabled and Available state. On the RAM side, the role's trust policy trusts the corresponding identity provider as guided by the IDaaS console, and the role's permission policy grants only the resource permissions that your workload requires.

Step 3: Create an M2M client and configure ACK OIDC federated credentials

Note

If an ACK federated trust source already exists, you can select it directly when you create an application federated credential. You do not need to create one for each M2M client.

  1. In the left-side navigation pane, click M2M Application.

  2. Click Add Application, and select the OIDC with M2M Application type.

  3. Enter the application name and other basic information, complete the creation, and record the client_id.

3.1 Enable ACK RRSA and inject an OIDC token into the pod

  1. On the Basic Information tab of the ACK cluster details page, go to Security and Auditing, turn on RRSA OIDC, and wait until the cluster returns to the Running state.

  2. On the cluster list page, click the target cluster name, and then in the left-side navigation pane, choose Add-ons.

  3. On the Add-ons page, find the ack-pod-identity-webhook add-on, and click Install in the lower-right corner of the add-on.

  4. Create or configure an RRSA RAM role. This role trusts the cluster's OIDC identity provider and restricts oidc:sub to system:serviceaccount:<namespace>:<serviceaccount>. This role is used only to trigger RRSA injection and does not replace the target cloud role in PAM.

  5. Add the label pod-identity.alibabacloud.com/injection: 'on' to the workload namespace, and add the annotation pod-identity.alibabacloud.com/role-name: <rrsa-ram-role-name> to the workload ServiceAccount.

  6. After you deploy the workload pod, run kubectl -n <namespace> get pod <pod-name> -o yaml and confirm that the ALIBABA_CLOUD_OIDC_TOKEN_FILE environment variable and the rrsa-oidc-token mount are injected.

For detailed instructions, see Use RRSA for pod-level access control.

3.2 Create or select an ACK OIDC federated trust source

  1. Go to Sign-in > Authentication Configuration > Federated Trust Source Management, and add a federated trust source of the OIDC type.

  2. Click Add federated trust source, and select the OIDC option.

  3. Configure the parameters:

    1. Federated trust source name: This document uses aliyun_ack.

    2. Network endpoint: This document uses Shared endpoint. IDaaS uses the network endpoint address to access the Issuer URL and obtain the public key over the OIDC protocol.

    3. Trust source: This document uses Issuer URL resolution.

    4. Issuer: The identity provider identifier. Obtain the provider URL from the ACK cluster information and enter it.

    5. Audience identifier: sts.aliyuncs.com (a fixed value for ACK).

    6. Trust condition: A condition expression for further authentication of ACK. This is optional and is not used in this document. If needed, see Use federated credential expressions to configure it.

  4. Complete the configuration.

3.3 Create an OIDC application federated credential for the M2M client

  1. Go to Application Management > M2M Application Management.

  2. Find the M2M client application, and click Manage.

  3. In General > Authentication Management, select the OIDC authentication type.

  4. Click Add federated credential, and configure the following:

    1. Federated trust source: Select aliyun_ack.

    2. Federated credential name: This document uses ack-oidc-credential. The application must pass this name when it obtains an M2M token, and the name must exactly match applicationFederatedCredentialName in client-config.json.

    3. Validation condition mode: Select Kubernetes mode.

    4. Namespace: The namespace where the container pod is deployed. This document uses default. The default namespace in Kubernetes is default; specify a value based on your environment.

    5. ServiceAccount: The ServiceAccount used by the container pod that runs the application. This example uses default. The default ServiceAccount in Kubernetes is default; specify a value based on your container pod.

  5. Complete the configuration.

Step 4: Grant PAM feature permissions

  1. In the left-side navigation pane, click Permission Center, and then select Feature Permission Management.

  2. On the Feature Permission Management page, search for the Privileged Access Management application, and click Authorization Management.

  3. Select Application Authorization. In Authorized Application, select the M2M client that you created in Step 3. In Select Permissions, search for and grant Obtain cloud role access credentials (cloud_account_role:obtain_access_credential).

Step 5: Grant data permissions for the cloud role

  1. In the left-side navigation pane, click Permission Center, and then select Data Permission Management.

  2. Add an authorization rule, enter its basic information, and then complete the creation.

  3. Select the authorization rule that you created, and click Permission Management.

  4. On the Associate Identity tab, select Application, and then select the M2M client that you created in Step 3.

  5. On the Asset Management tab, select Cloud Role, click Add Asset, and select the target cloud role from Step 2 that obtains the final STS token.

Step 6: Download and import the IDaaS SDK

  1. On GitHub, get the latest version of the IDaaS SDK. Only Java and Python are currently supported.

  2. Configure the dependencies as described in the SDK README.md.

Step 7: Create the SDK configuration file

  1. Create a client-config.json file. By default, you can place it at ~/.cloud_idaas/client-config.json.

  2. On GitHub, find the IDaaS Core SDK.

  3. In the SDK's GitHub repository, review the README.md file, find the OIDC client-config.json example, and copy it into the client-config.json file that you created. The following example shows the configuration:

{
  "idaasInstanceId": "idaas_xxx",
  "clientId": "app_xxx",
  "issuer": "https://xxx/api/v2/iauths_system/oauth2",
  "tokenEndpoint": "https://xxx/api/v2/iauths_system/oauth2/token",
  "scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential",
  "openApiEndpoint": "eiam.[region_id].aliyuncs.com",
  "developerApiEndpoint": "eiam-developerapi.[region_id].aliyuncs.com",
  "authnConfiguration": {
    "identityType": "CLIENT",
    "authnMethod": "OIDC",
    "applicationFederatedCredentialName": "ack-oidc-credential",
    "clientDeployEnvironment": "KUBERNETES",
    "oidcTokenFilePathEnvVarName": "ALIBABA_CLOUD_OIDC_TOKEN_FILE"
  },
  "httpConfiguration": {
    "connectTimeout": 5000,
    "readTimeout": 10000
  }
}

Parameter

Value

Description

idaasInstanceId

idaas_xxx

The ID of the IDaaS instance.

clientId

app_xxx

The client_id of the M2M client that you created in Step 3.

issuer

https://xxx/api/v2/iauths_system/oauth2

Replace xxx with the IDaaS user portal address.

tokenEndpoint

https://xxx/api/v2/iauths_system/oauth2/token

The IDaaS token endpoint.

scope

A fixed value. See the JSON configuration above.

The scope that PAM uses to obtain cloud role access credentials.

openApiEndpoint

eiam.[region_id].aliyuncs.com

Optional. region_id is the region of the IDaaS instance, for example, cn-hangzhou.

developerApiEndpoint

eiam-developerapi.[region_id].aliyuncs.com

Required. region_id is the region of the IDaaS instance, for example, cn-hangzhou.

authnConfiguration

└identityType

CLIENT

A fixed value.

└authnMethod

OIDC

A fixed value. Uses OIDC federated authentication.

└applicationFederatedCredentialName

ack-oidc-credential

The name of the application federated credential that you created in Step 3.3.

└clientDeployEnvironment

KUBERNETES

A fixed value that indicates the application runs in a Kubernetes pod.

└oidcTokenFilePathEnvVarName

ALIBABA_CLOUD_OIDC_TOKEN_FILE

A fixed value. The SDK reads the OIDC token from the token file path specified by this environment variable.

httpConfiguration

└connectTimeout

5000

The maximum time to wait for a connection to be established, in milliseconds.

└readTimeout

10000

The maximum time to wait for a server response after the connection is established, in milliseconds.

Step 8: Integrate the code

Complete the following operations by referring to the SDK quick start:

  1. Initialize the IDaaS Core SDK.

  2. Pass in the target cloud role ARN to create the Alibaba Cloud credentials provider.

  3. Obtain the temporary STS credentials.

    public static void main(String[] args) {
        // 1. Initialize the IDaaS Core SDK
        IDaaSCredentialProviderFactory.init();
        // 2. Create the Alibaba Cloud credentials provider
        AlibabaCloudCredentialsProvider credentialsProvider =
                IDaaSPamAklessCredentialFactory.getAlibabaCloudCredentialsProvider(
                        "acs:ram::123456789:role/your-role-name"
                );
        // 3. Obtain the credentials
        CredentialModel credentials = credentialsProvider.getCredentials();
        System.out.println(credentials.getAccessKeyId());
        System.out.println(credentials.getAccessKeySecret());
        System.out.println(credentials.getSecurityToken());
    }

Verify the result

  1. Confirm that RRSA has injected the ALIBABA_CLOUD_OIDC_TOKEN_FILE environment variable and the rrsa-oidc-token mount into the workload pod.

  2. Place the configuration file from Step 7 at the default path ~/.cloud_idaas/client-config.json.

  3. Deploy the workload pod that uses the namespace and ServiceAccount from Step 3.3.

  4. Run the application in the pod and confirm that it can obtain temporary STS credentials.

  5. Use the temporary credentials to call the cloud service API operations that the target cloud role's permission policy allows.