All Products
Search
Document Center

Identity as a Service:Best practice: obtain STS credentials on ECS without static credentials

Last Updated:Sep 24, 2026

For applications that run on ECS, obtain temporary STS credentials for a specific RAM role without static credentials, by combining PKCS#7 federated authentication based on ECS instance metadata with PAM authorization.

How it works

An M2M client application that runs on ECS calls the IDaaS SDK. The SDK automatically retrieves PKCS#7 attestation material from the ECS metadata service to complete federated authentication for the M2M client application. The SDK then uses the resulting token to call PAM and obtain temporary STS credentials for the target cloud role. The application does not need to store a client secret or a long-term AccessKey.

Prerequisites

  • The Machine Identity Management and Privileged Access Management capabilities of IDaaS EIAM are enabled.

  • You have RAM administrative permissions and have identified the least privileges that the target RAM role needs.

  • You have administrative permissions for the ECS instance and its related configurations, and the ECS instance can reach the public endpoint of the EIAM instance.

References

Configuration steps

Step 1: Add a cloud account and system cloud role in Asset Management

In the IDaaS EIAM console, go to Asset Management > Cloud Identity and add the target Alibaba Cloud account. Follow the console prompts to configure the identity provider, system cloud role, and detection items, and confirm that both the cloud account and the system cloud role are in the Available state. For reference:

Step 2: Add the target cloud role that obtains the final STS credentials

In Cloud Role Management for the managed cloud account, add the target RAM role. Confirm that the cloud role is in the Enabled and Available state. On the RAM side, the role's trust policy trusts the corresponding identity provider as guided by the IDaaS console, and the role's permission policy grants only the resource permissions that your workload requires.

Step 3: Create an M2M client and configure PKCS#7 federated credentials

Note

If an ECS federated trust source already exists, you can select it directly when you create an application federated credential. You do not need to create one for each M2M client.

  1. In the left-side navigation pane, click M2M Application.

  2. Click Add Application, and select the OIDC with M2M Application type.

  3. Enter the application name and other basic information, complete the creation, and record the client_id.

  4. Go to Sign-in > Authentication Configuration > Federated Trust Source Management. If a PKCS#7 federated trust source that matches the current Alibaba Cloud account already exists, select it directly; you do not need to create one for each M2M client. Create a new federated trust source as described in the following table only when no reusable one exists.

Parameter

Value

Federated trust source type

PKCS#7

Trust source

Alibaba Cloud

Signature validity period

Use the console default value.

Signature verification certificate

After you select the trust source, click Get cloud provider certificate.

Cloud account ID

The ID of the Alibaba Cloud account where the ECS instance is deployed.

  1. Open General > Authentication Management for the M2M client, select PKCS#7, and add an application federated credential.

Parameter

Value

Federated trust source

Select the PKCS#7 federated trust source that you created in the previous step or an existing one.

Federated credential name

A custom name, for example, ecs-pkcs7-credential.

Validation condition mode

The specified ECS instance mode.

ECS instance ID

The ID of the ECS instance that runs the application.

Note

Record the federated credential name. You cannot change it after creation, and it must exactly match the value of applicationFederatedCredentialName in Step 7.

Step 4: Grant PAM feature permissions

  1. In the left-side navigation pane, click Permission Center, and then select Feature Permission Management.

  2. On the Feature Permission Management page, search for the Privileged Access Management application, and click Authorization Management.

  3. Select Application Authorization. In Authorized Application, select the M2M client that you created. In Select Permissions, search for and grant Obtain cloud role access credentials (cloud_account_role:obtain_access_credential).

Step 5: Grant data permissions for the cloud role

  1. In the left-side navigation pane, click Permission Center, and then select Data Permission Management.

  2. Add an authorization rule, enter its basic information, and then complete the creation.

  3. Select the authorization rule that you created, and click Permission Management.

  4. On the Associate Identity tab, select Application, and then select the M2M client that you created.

  5. On the Asset Management tab, select Cloud Role, click Add Asset, and select the target cloud role that obtains the final STS token.

Step 6: Download and import the IDaaS SDK

  1. On GitHub, get the latest version of the IDaaS SDK. Only Java and Python are currently supported.

  2. Configure the dependencies as described in the SDK README.

Step 7: Create the SDK configuration file

  1. Create a client-config.json file. By default, you can place it at ~/.cloud_idaas/client-config.json.

  2. On GitHub, find the IDaaS Core SDK.

  3. In the SDK's GitHub repository, review the README.md or README_zh.md file, find the PKCS#7 client-config.json example, and copy it into the client-config.json file that you created. The following example shows the configuration:

{
  "idaasInstanceId": "idaas_xxx",
  "clientId": "app_xxx",
  "issuer": "https://xxx/api/v2/iauths_system/oauth2",
  "tokenEndpoint": "https://xxx/api/v2/iauths_system/oauth2/token",
  "scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential",
  "openApiEndpoint": "eiam.[region_id].aliyuncs.com",
  "developerApiEndpoint": "eiam-developerapi.[region_id].aliyuncs.com",
  "authnConfiguration": {
    "identityType": "CLIENT",
    "authnMethod": "PKCS7",
    "applicationFederatedCredentialName": "ecs-pkcs7-credential",
    "clientDeployEnvironment": "ALIBABA_CLOUD_ECS"
  },
  "httpConfiguration": {
    "connectTimeout": 5000,
    "readTimeout": 10000
  }
}

Parameter

Value

Description

idaasInstanceId

idaas_xxx

The ID of the IDaaS instance.

clientId

app_xxx

The client_id of the M2M client that you created in Step 3.

issuer

https://xxx/api/v2/iauths_system/oauth2

Replace xxx with the IDaaS user portal address, which you can find on the IDaaS instance list page.

tokenEndpoint

https://xxx/api/v2/iauths_system/oauth2/token

scope

A fixed value. See the JSON configuration above.

The scope that PAM uses to obtain cloud role access credentials.

openApiEndpoint

eiam.[region_id].aliyuncs.com

Replace region_id with the region ID of the IDaaS instance. Example: cn-hangzhou.

developerApiEndpoint

eiam-developerapi.[region_id].aliyuncs.com

authnConfiguration

└identityType

CLIENT

A fixed value.

└authnMethod

PKCS7

A fixed value. Uses PKCS#7 federated authentication.

└applicationFederatedCredentialName

ecs-pkcs7-credential

The name of the application federated credential that you created in Step 3.

└clientDeployEnvironment

ALIBABA_CLOUD_ECS

A fixed value. The SDK uses it to retrieve PKCS#7 attestation material from the ECS metadata service.

httpConfiguration

└connectTimeout

5000

The maximum time to wait for a connection to be established, in milliseconds (ms).

└readTimeout

10000

The maximum time to wait for a server response after the connection is established, in milliseconds (ms).

Step 8: Integrate the code

Complete the following operations by referring to the SDK quick start:

  1. Initialize the IDaaS Core SDK.

  2. Pass in the target cloud role ARN to create the Alibaba Cloud credentials provider.

  3. Obtain the temporary STS credentials.

    public static void main(String[] args) {
        // 1. Initialize the IDaaS Core SDK
        IDaaSCredentialProviderFactory.init();
        // 2. Create the Alibaba Cloud credentials provider
        AlibabaCloudCredentialsProvider credentialsProvider =
                IDaaSPamAklessCredentialFactory.getAlibabaCloudCredentialsProvider(
                        "acs:ram::123456789:role/your-role-name"
                );
        // 3. Obtain the credentials
        CredentialModel credentials = credentialsProvider.getCredentials();
        System.out.println(credentials.getAccessKeyId());
        System.out.println(credentials.getAccessKeySecret());
        System.out.println(credentials.getSecurityToken());
    }

Verify the result

  1. Place the configuration file from Step 7 at the default path ~/.cloud_idaas/client-config.json.

  2. Run the application on the ECS instance that you specified in Step 3.

  3. Confirm that the output contains AccessKeyId, AccessKeySecret, SecurityToken, and Expiration.

  4. Use the temporary credentials to call the cloud service API operations that the target cloud role's permission policy allows.