Class RestApiMetadataExtensions
- Namespace
- Songhay.S3.Extensions
- Assembly
- SonghayCore.S3.dll
Extensions of RestApiMetadata
public static class RestApiMetadataExtensions
- Inheritance
-
RestApiMetadataExtensions
- Inherited Members
Methods
ToS3LessSecureTuple(RestApiMetadata?, string?, ILogger)
Returns a tuple, decomposing the specified RestApiMetadata into:
- the S3 ‘public’ key (
AWS_ACCESS_KEY_ID) - the S3 ‘private’ key (
AWS_SECRET_ACCESS_KEY) - the S3 bucket name
- the S3 bucket region
- the base URI of the bucket
public static (string? publicKey, string? privateKey, string? bucketName, string? region, string? uriRoot) ToS3LessSecureTuple(this RestApiMetadata? meta, string? bucketMetaKey, ILogger logger)
Parameters
metaRestApiMetadatathe RestApiMetadata
bucketMetaKeystringthe ClaimsSet dictionary key
loggerILoggerthe ILogger
Returns
Remarks
This transformation is called ‘less secure’ because the S3 ‘public’/‘private’ keys are exposed to the developer/consumer explicitly which encourages security risks.
Surely, Amazon recommends using the Amazon.Runtime.CredentialManagement.CredentialProfileStoreChain which can lead to leveraging an “underlying orchestration layer” (e.g. a layer with EKS Pod Identity) instead of handling secrets explicitly.
To use the ProgramMetadata convention of this Studio without handling secrets explicitly, use ToS3Tuple(RestApiMetadata?, string?, ILogger) instead.
See the remarks for ToS3Tuple(RestApiMetadata?, string?, ILogger).
ToS3Tuple(RestApiMetadata?, string?, ILogger)
Returns a tuple, decomposing the specified RestApiMetadata into:
- AWS credentials profile name (on Linux in the
~/.aws/credentialsfile) - the S3 bucket name
- the S3 bucket region
- the base URI of the bucket
public static (string? credentialsProfileName, string? bucketName, string? region, string? uriRoot) ToS3Tuple(this RestApiMetadata? meta, string? bucketMetaKey, ILogger logger)
Parameters
metaRestApiMetadatathe RestApiMetadata
bucketMetaKeystringthe ClaimsSet dictionary key
loggerILoggerthe ILogger
Returns
Remarks
The JSON shaped like RestApiMetadata can look like this:
"Wasabi": {
"ClaimsSet": {
"aws-credentials-profile-name": "???",
"bucket-region-suffix": "-region",
"public-key": "???",
"private-key": "??",
"bucket-location-template": "https://s3.{Region}.wasabisys.com/",
"bucket-location-template-placeholder": "{Region}",
"my-bucket-region": "us-central-1"
}
}
…where the name of the bucket, my-bucket, is ‘embedded’
in the my-bucket-region key-value pair.