Skip to main content

Support Automatic Credential Refresh

We have spacelift stacks that can take longer than 1 hour, which is the hard limit of chained AWS IAM Role Assumptions. Spacelift should support allowing users to enable automatic credential refresh before they expire.

Workaround
No
Problem
Status: ❌ Rejected2 comments

Log in to comment and vote

Comments2

  • Pink Octopus

    •

    Apr 29, 2025

    Thanks for raising this request. While we’re not planning to implement this natively at this time, there is a workaround available. You could use the OIDC token spacelift generates on disk to authenticate in a hook with OIDC to AWS. This will allow you to use the maximum session length of the role in AWS.

    Please note that this method involves a more manual setup compared to our built-in cloud integrations.

    Best Regards,

    Spacelift Product team.

  • Maroon Leaf

    •

    Apr 24, 2025

    This issue is problematic for production-ready complex deployments that involve provisioning a large number of resources, such as databases, during a single run. The current one-hour limit often leads to deployment failures and requires manual intervention to resume. While subsequent runs may pick up where the previous one left off, this is not a viable solution for automated, production-grade deployments.

    We request a solution that allows Spacelift to handle deployments that exceed the one-hour limit. Here are a couple of potential solutions:

    • Automatic Token Renewal: Investigate and implement a mechanism for Spacelift to automatically renew the AWS role session token before it expires. This would allow the run to continue uninterrupted.

    • Enhanced OIDC Integration: Improve the existing OIDC integration to simplify its setup and make it a more practical alternative to role chaining. The current workaround suggested by support involves using the OIDC token Spacelift generates on disk to authenticate in a hook with OIDC to AWS. This allows for longer session lengths but requires more manual configuration. Simplifying this process would be beneficial.