For applications that run on ECS, obtain temporary STS credentials for a specific RAM role without static credentials, by combining PKCS#7 federated authentication based on ECS instance metadata with PAM authorization.
How it works
An M2M client application that runs on ECS calls the IDaaS SDK. The SDK automatically retrieves PKCS#7 attestation material from the ECS metadata service to complete federated authentication for the M2M client application. The SDK then uses the resulting token to call PAM and obtain temporary STS credentials for the target cloud role. The application does not need to store a client secret or a long-term AccessKey.
Prerequisites
The Machine Identity Management and Privileged Access Management capabilities of IDaaS EIAM are enabled.
You have RAM administrative permissions and have identified the least privileges that the target RAM role needs.
You have administrative permissions for the ECS instance and its related configurations, and the ECS instance can reach the public endpoint of the EIAM instance.
References
Configuration steps
Step 1: Add a cloud account and system cloud role in Asset Management
In the IDaaS EIAM console, go to Asset Management > Cloud Identity and add the target Alibaba Cloud account. Follow the console prompts to configure the identity provider, system cloud role, and detection items, and confirm that both the cloud account and the system cloud role are in the Available state. For reference:
Step 2: Add the target cloud role that obtains the final STS credentials
In Cloud Role Management for the managed cloud account, add the target RAM role. Confirm that the cloud role is in the Enabled and Available state. On the RAM side, the role's trust policy trusts the corresponding identity provider as guided by the IDaaS console, and the role's permission policy grants only the resource permissions that your workload requires.
Step 3: Create an M2M client and configure PKCS#7 federated credentials
If an ECS federated trust source already exists, you can select it directly when you create an application federated credential. You do not need to create one for each M2M client.
In the left-side navigation pane, click M2M Application.
Click Add Application, and select the OIDC with M2M Application type.
Enter the application name and other basic information, complete the creation, and record the
client_id.Go to Sign-in > Authentication Configuration > Federated Trust Source Management. If a PKCS#7 federated trust source that matches the current Alibaba Cloud account already exists, select it directly; you do not need to create one for each M2M client. Create a new federated trust source as described in the following table only when no reusable one exists.
Parameter | Value |
Federated trust source type | PKCS#7 |
Trust source | Alibaba Cloud |
Signature validity period | Use the console default value. |
Signature verification certificate | After you select the trust source, click Get cloud provider certificate. |
Cloud account ID | The ID of the Alibaba Cloud account where the ECS instance is deployed. |
Open General > Authentication Management for the M2M client, select PKCS#7, and add an application federated credential.
Parameter | Value |
Federated trust source | Select the PKCS#7 federated trust source that you created in the previous step or an existing one. |
Federated credential name | A custom name, for example, |
Validation condition mode | The specified ECS instance mode. |
ECS instance ID | The ID of the ECS instance that runs the application. |
Record the federated credential name. You cannot change it after creation, and it must exactly match the value of applicationFederatedCredentialName in Step 7.
Step 4: Grant PAM feature permissions
In the left-side navigation pane, click Permission Center, and then select Feature Permission Management.
On the Feature Permission Management page, search for the
Privileged Access Managementapplication, and click Authorization Management.Select Application Authorization. In Authorized Application, select the M2M client that you created. In Select Permissions, search for and grant Obtain cloud role access credentials (
cloud_account_role:obtain_access_credential).
Step 5: Grant data permissions for the cloud role
In the left-side navigation pane, click Permission Center, and then select Data Permission Management.
Add an authorization rule, enter its basic information, and then complete the creation.
Select the authorization rule that you created, and click Permission Management.
On the Associate Identity tab, select Application, and then select the M2M client that you created.
On the Asset Management tab, select Cloud Role, click Add Asset, and select the target cloud role that obtains the final STS token.
Step 6: Download and import the IDaaS SDK
On GitHub, get the latest version of the IDaaS SDK. Only Java and Python are currently supported.
Configure the dependencies as described in the SDK README.
Step 7: Create the SDK configuration file
Create a
client-config.jsonfile. By default, you can place it at~/.cloud_idaas/client-config.json.On GitHub, find the
IDaaS Core SDK.In the SDK's GitHub repository, review the
README.mdorREADME_zh.mdfile, find the PKCS#7 client-config.json example, and copy it into theclient-config.jsonfile that you created. The following example shows the configuration:
{
"idaasInstanceId": "idaas_xxx",
"clientId": "app_xxx",
"issuer": "https://xxx/api/v2/iauths_system/oauth2",
"tokenEndpoint": "https://xxx/api/v2/iauths_system/oauth2/token",
"scope": "urn:cloud:idaas:pam|cloud_account_role:obtain_access_credential",
"openApiEndpoint": "eiam.[region_id].aliyuncs.com",
"developerApiEndpoint": "eiam-developerapi.[region_id].aliyuncs.com",
"authnConfiguration": {
"identityType": "CLIENT",
"authnMethod": "PKCS7",
"applicationFederatedCredentialName": "ecs-pkcs7-credential",
"clientDeployEnvironment": "ALIBABA_CLOUD_ECS"
},
"httpConfiguration": {
"connectTimeout": 5000,
"readTimeout": 10000
}
}Parameter | Value | Description |
|
| The ID of the IDaaS instance. |
|
| The |
|
| Replace xxx with the IDaaS user portal address, which you can find on the IDaaS instance list page. |
|
| |
| A fixed value. See the JSON configuration above. | The scope that PAM uses to obtain cloud role access credentials. |
|
| Replace region_id with the region ID of the IDaaS instance. Example: cn-hangzhou. |
|
| |
| ||
└ |
| A fixed value. |
└ |
| A fixed value. Uses PKCS#7 federated authentication. |
└ |
| The name of the application federated credential that you created in Step 3. |
└ |
| A fixed value. The SDK uses it to retrieve PKCS#7 attestation material from the ECS metadata service. |
| ||
└ | 5000 | The maximum time to wait for a connection to be established, in milliseconds (ms). |
└ | 10000 | The maximum time to wait for a server response after the connection is established, in milliseconds (ms). |
Step 8: Integrate the code
Complete the following operations by referring to the SDK quick start:
Initialize the IDaaS Core SDK.
Pass in the target cloud role ARN to create the Alibaba Cloud credentials provider.
Obtain the temporary STS credentials.
public static void main(String[] args) {
// 1. Initialize the IDaaS Core SDK
IDaaSCredentialProviderFactory.init();
// 2. Create the Alibaba Cloud credentials provider
AlibabaCloudCredentialsProvider credentialsProvider =
IDaaSPamAklessCredentialFactory.getAlibabaCloudCredentialsProvider(
"acs:ram::123456789:role/your-role-name"
);
// 3. Obtain the credentials
CredentialModel credentials = credentialsProvider.getCredentials();
System.out.println(credentials.getAccessKeyId());
System.out.println(credentials.getAccessKeySecret());
System.out.println(credentials.getSecurityToken());
}Verify the result
Place the configuration file from Step 7 at the default path
~/.cloud_idaas/client-config.json.Run the application on the ECS instance that you specified in Step 3.
Confirm that the output contains
AccessKeyId,AccessKeySecret,SecurityToken, andExpiration.Use the temporary credentials to call the cloud service API operations that the target cloud role's permission policy allows.