Support Automatic Credential Refresh
We have spacelift stacks that can take longer than 1 hour, which is the hard limit of chained AWS IAM Role Assumptions. Spacelift should support allowing users to enable automatic credential refresh before they expire.
- Workaround
- No
- Problem
Log in to comment and vote
Comments2
Pink Octopus
Apr 29, 2025
Thanks for raising this request. While we’re not planning to implement this natively at this time, there is a workaround available. You could use the OIDC token spacelift generates on disk to authenticate in a hook with OIDC to AWS. This will allow you to use the maximum session length of the role in AWS.
Please note that this method involves a more manual setup compared to our built-in cloud integrations.
Best Regards,
Spacelift Product team.
Maroon Leaf
Apr 24, 2025
This issue is problematic for production-ready complex deployments that involve provisioning a large number of resources, such as databases, during a single run. The current one-hour limit often leads to deployment failures and requires manual intervention to resume. While subsequent runs may pick up where the previous one left off, this is not a viable solution for automated, production-grade deployments.
We request a solution that allows Spacelift to handle deployments that exceed the one-hour limit. Here are a couple of potential solutions:
Automatic Token Renewal: Investigate and implement a mechanism for Spacelift to automatically renew the AWS role session token before it expires. This would allow the run to continue uninterrupted.
Enhanced OIDC Integration: Improve the existing OIDC integration to simplify its setup and make it a more practical alternative to role chaining. The current workaround suggested by support involves using the OIDC token Spacelift generates on disk to authenticate in a hook with OIDC to AWS. This allows for longer session lengths but requires more manual configuration. Simplifying this process would be beneficial.