# SNS Output - Logstash in EKS - using fine grained Service account IAM roles

**URL:** <https://discuss.elastic.co/t/sns-output-logstash-in-eks-using-fine-grained-service-account-iam-roles/202847>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [October 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/sns-output-logstash-in-eks-using-fine-grained-service-account-iam-roles/202847 "2019-10-09T14:26:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![chandra2037](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chandra2037/32/72142_2.png) [@chandra2037](https://discuss.elastic.co/u/chandra2037)\
**Post date:** [October 9, 2019, 2:26pm UTC](https://discuss.elastic.co/t/sns-output-logstash-in-eks-using-fine-grained-service-account-iam-roles/202847/1 "2019-10-09T14:26:25Z")

</div>

Elasticsearch Version: 7.4.0  
Logstash Version: 7.4.0

Deployed in Amazon EKS as a POD using official [Logstash Docker](https://www.docker.elastic.co/#logstash-7-4-0) container.

Trying to publish messages to [Amazon SNS](https://docs.aws.amazon.com/sns/latest/dg/welcome.html) using Logstash [SNS output](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-sns.html) plugin.

Amazon introduced [Fine-Grained IAM Roles](https://aws.amazon.com/blogs/opensource/introducing-fine-grained-iam-roles-service-accounts/) for EKS Service Accounts to give fine-grained IAM role to Pods rather than EKS nodes.

Created [IAM role](https://docs.aws.amazon.com/eks/latest/userguide/create-service-account-iam-policy-and-role.html) with SNS:Publish access, and also service account with this new role.

Providing the service account details to the Logstash deployment manifest file. After deployment, I am seeing `aws-iam-token` volume which contains the `AWS_WEB_IDENTITY_TOKEN_FILE`, and also `AWS_IAM_ROLE_ARN` as environment variable.

Now coming to configuring SNS output, I am seeing following options to configure the access to publish messages to SNS

- [`access_key_id`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-sns.html#plugins-outputs-sns-access_key_id)
- [`aws_credentials_file`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-sns.html#plugins-outputs-sns-aws_credentials_file)
- [`secret_access_key`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-sns.html#plugins-outputs-sns-secret_access_key)
- [`session_token`](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-sns.html#plugins-outputs-sns-session_token)

Since I have token file, I configured the `session_token` to point to the `AWS_WEB_IDENTITY_TOKEN_FILE` location. Also, I tried configuring `AWS_IAM_ROLE_ARN` as `access_key_id`.

But Logstash not able to publish messages to SNS, it is giving permission error. By default, it is assuming the EKS node role, and node role do not have access to publish messages to SNS. Configuring the `session_token` having no impact.

Am I missing something in the Output configuration?

Also noticed the following in the AWS documentation, not sure SDK version has any impact on this?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f210f6b847c4bea49bb31995ff61c2271fa8d16e.png)

Thank you for any input on this issue.

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [October 14, 2019, 9:32pm UTC](https://discuss.elastic.co/t/sns-output-logstash-in-eks-using-fine-grained-service-account-iam-roles/202847/2 "2019-10-14T21:32:47Z")

</div>

It looks like the current release of the SNS Output Plugin does not have a feature to read credentials from a file; both `session_token` and `secret_access_key` expect the key provided to be a literal string (not a file path), and `aws_credentials_file` is merely a file-based way of providing these two as a key/value file in a specific format.

Additionally, Logstash 7.4.0 ships with AWS SDK 2.11.343, so it does _not_ support the `sts:AssumeRoleWithWebIdentity` credential provider:

> ```auto
> aws-sdk (2.11.343)
> 
> ```
> 
> -- [Gemfile.jruby-2.5.lock.release:45@v7.4.0](https://github.com/elastic/logstash/blob/v7.4.0/Gemfile.jruby-2.5.lock.release#L45)

* * *

Right now the primary blocker to upgrading the AWS SDK that is shipped with these plugins is the sheer number of plugins that rely on the SDK requires that all are updated in lock-step to avoid dependency conflicts. We have work in-flight that mitigates this by distributing related plugins as a single "integration" plugin from a shared code-base, and regrouping the AWS plugins is on our to-do list.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2019, 9:32pm UTC](https://discuss.elastic.co/t/sns-output-logstash-in-eks-using-fine-grained-service-account-iam-roles/202847/3 "2019-11-11T21:32:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
