Table of Contents

Class RestApiMetadataExtensions

Namespace
Songhay.S3.Extensions
Assembly
SonghayCore.S3.dll

Extensions of RestApiMetadata

public static class RestApiMetadataExtensions
Inheritance
RestApiMetadataExtensions
Inherited Members

Methods

ToS3LessSecureTuple(RestApiMetadata?, string?, ILogger)

Returns a tuple, decomposing the specified RestApiMetadata into:

  • the S3 ‘public’ key (AWS_ACCESS_KEY_ID)
  • the S3 ‘private’ key (AWS_SECRET_ACCESS_KEY)
  • the S3 bucket name
  • the S3 bucket region
  • the base URI of the bucket
public static (string? publicKey, string? privateKey, string? bucketName, string? region, string? uriRoot) ToS3LessSecureTuple(this RestApiMetadata? meta, string? bucketMetaKey, ILogger logger)

Parameters

meta RestApiMetadata

the RestApiMetadata

bucketMetaKey string

the ClaimsSet dictionary key

logger ILogger

the ILogger

Returns

(string publicKey, string privateKey, string bucketName, string region, string uriRoot)

Remarks

This transformation is called ‘less secure’ because the S3 ‘public’/‘private’ keys are exposed to the developer/consumer explicitly which encourages security risks.

Surely, Amazon recommends using the Amazon.Runtime.CredentialManagement.CredentialProfileStoreChain which can lead to leveraging an “underlying orchestration layer” (e.g. a layer with EKS Pod Identity) instead of handling secrets explicitly.

To use the ProgramMetadata convention of this Studio without handling secrets explicitly, use ToS3Tuple(RestApiMetadata?, string?, ILogger) instead.

See the remarks for ToS3Tuple(RestApiMetadata?, string?, ILogger).

ToS3Tuple(RestApiMetadata?, string?, ILogger)

Returns a tuple, decomposing the specified RestApiMetadata into:

  • AWS credentials profile name (on Linux in the ~/.aws/credentials file)
  • the S3 bucket name
  • the S3 bucket region
  • the base URI of the bucket
public static (string? credentialsProfileName, string? bucketName, string? region, string? uriRoot) ToS3Tuple(this RestApiMetadata? meta, string? bucketMetaKey, ILogger logger)

Parameters

meta RestApiMetadata

the RestApiMetadata

bucketMetaKey string

the ClaimsSet dictionary key

logger ILogger

the ILogger

Returns

(string credentialsProfileName, string bucketName, string region, string uriRoot)

Remarks

The JSON shaped like RestApiMetadata can look like this:

"Wasabi": {
    "ClaimsSet": {
        "aws-credentials-profile-name": "???",
        "bucket-region-suffix": "-region",
        "public-key": "???",
        "private-key": "??",
        "bucket-location-template": "https://s3.{Region}.wasabisys.com/",
        "bucket-location-template-placeholder": "{Region}",
        "my-bucket-region": "us-central-1"
    }
}

…where the name of the bucket, my-bucket, is ‘embedded’ in the my-bucket-region key-value pair.