# AWS module credentials configuration: support default credentials provider

**URL:** <https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440>\
**Category:** Beats\
**Created:** [June 25, 2019, 10:30pm UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440 "2019-06-25T22:30:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [June 25, 2019, 10:30pm UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440/1 "2019-06-25T22:30:09Z")

</div>

Hi,

We'd prefer to mount an AWS credentials file into our docker containers at `/root/.aws/credentials` versus specifing `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` as env variables.

I'd assume that the sdk would still pick this up, however filebeat config validation fails with

```auto
2019-06-25T22:24:06.064Z ERROR instance/beat.go:877 Exiting: empty field accessing '0.access_key_id' (source:'/usr/share/metricbeat/modules.d/aws.yml')
Exiting: empty field accessing '0.access_key_id' (source:'/usr/share/metricbeat/modules.d/aws.yml')

```

Is this a reasonable ask? I wanted to run it by the group here before opening a ticket on github.

Thanks, Justin

---

<div class="post-metadata">

**Author:** ![martinr\_ubi](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@martinr\_ubi](https://discuss.elastic.co/u/martinr_ubi)\
**Post date:** [June 26, 2019, 1:16am UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440/2 "2019-06-26T01:16:27Z")

</div>

Yes definetely, if the module doesn’t support the normal credential provider chain that all aws SDK use and that all AWS user expect... I would be tempted to say thats a bug because it is so ingrained in the AWS ecosystem.

By supporting the normal SDK behavior you get support for on prem, on prem with AWS SSM installed, EC2 instances with instance role and ECS task role.

Forcing one to supply creds when metricbeat is running inside an ec2 instance with a role for example... is weird.

I have to guess they already have that knowledge in GO at least because of Functionbeat which runs in a lambda?  
They also do it in the EC2 discovery plugin and the S3 snapshot repository plugin, although those are Java and from different internal teams at Elastic I would assume.

Short if there is not already an issue, do open one and link here.

[https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html](https://docs.aws.amazon.com/sdk-for-go/v1/developer-guide/configuring-sdk.html)

---

<div class="post-metadata">

**Author:** ![justinw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justinw/32/40277_2.png) [@justinw](https://discuss.elastic.co/u/justinw)\
**Post date:** [June 27, 2019, 5:53pm UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440/3 "2019-06-27T17:53:18Z")

</div>

Issue created here [https://github.com/elastic/beats/issues/12708](https://github.com/elastic/beats/issues/12708)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 25, 2019, 7:53pm UTC](https://discuss.elastic.co/t/aws-module-credentials-configuration-support-default-credentials-provider/187440/4 "2019-07-25T19:53:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
