Plugin is not resolving correct profile in .aws/credentials

#16 · closed · 9 comments

View on GitHub ↗

mfulleratlassian

Because the code in this plugin defines its own AWS objects it is not respecting the correct profile inside ~/.aws/credentials To reproduce remove your default profile from ~/.aws/credentials and try and deploy a function. error: `e { CredentialsError: Missing credentials in config at Object.parse (native) at /Users/mfuller/node_modules/aws-sdk/lib/metadata_service.js:115:38 at IncomingMessage.<anonymous> (/Users/mfuller/node_modules/aws-sdk/lib/metadata_service.js:74:45) at emitNone (events.js:91:20) at IncomingMessage.emit (events.js:185:7) at endReadableNT (_stream_readable.js:926:12) at _combinedTickCallback (internal/process/next_tick.js:74:11) at process._tickDomainCallback (internal/process/next_tick.js:122:9) message: 'Missing credentials in config', code: 'CredentialsError', time: 2016-07-12T21:09:50.459Z, originalError: { message: 'Could not load credentials from any providers', code: 'CredentialsError', time: 2016-07-12T21:09:50.459Z, originalError: { message: 'Unexpected token < in JSON at position 0' } } } Serverless: error in creating alerts` Suggested fix: Replace all AWS calls with the serverless calls like so: `_this.aws.request('SERVICENAME', 'API_CALL', params, _this.evt.options.stage, _this.evt.options.region)`

Comments

mfulleratlassian

If I get some time over the next few days I will write a PR for your review.

martinlindenberg

I cannot reproduce this error - sorry. In my development environment i am using the `admin.env` file, where i define which AWS profile to use. ``` AWS_DEV_PROFILE=testing-account AWS_STAGING_PROFILE=testing-account AWS_TESTING_PROFILE=testing-account AWS_LIVE_PROFILE=live-account ``` if i rename the `default` account, it still works without any errors (expected). if i rename `testing-account` it fails with another error during deployment of the function. The plugin is not invoked in that case...

mfulleratlassian

You don't have credentials in your environment?

mfulleratlassian

admin.env ``` AWS_DEV_PROFILE=training AWS_PROD_PROFILE=training ``` ~/.aws/credentials ``` [training] aws_access_key_id = <redacted> aws_secret_access_key = <redacted> default_region = us-east-1 ``` s-project.json ``` { "name": "kmscreate", "custom": {}, "plugins": [ "serverless-plugin-alerting" ] } ``` npm install ``` [email protected] /Users/mfuller/stash/kmscreate └─┬ [email protected] └── [email protected] ``` sls function create -r python2.7 -t function src/test ``` Serverless: Successfully created function: "src/test" ``` vi src/test/alerting.json ``` [ { "notificationTopicStageMapping": { "dev": "mfuller" }, "alerts": { "Errors": { "enabled": true, "alarmNamespace": "AWS/Lambda", "description": "Alarm if function returns an error", "alarmStatisticType": "Sum", "alarmPeriod": "60", "alarmThreshold": "10", "comparisonOperator": "GreaterThanOrEqualToThreshold", "evaluationPeriod": "5" }, "Throttles": { "enabled": true, "alarmNamespace": "AWS/Lambda", "description": "Alarm if function has more than 5 throttled requests", "alarmStatisticType": "Sum", "alarmPeriod": "60", "alarmThreshold": "10", "comparisonOperator": "GreaterThanOrEqualToThreshold", "evaluationPeriod": "5" } } } ] ``` cd src/test/ && sls function deploy -s dev -r us-east-1 ``` Serverless: Deploying the specified functions in "dev" to the following regions: us-east-1 Serverless: ------------------------ Serverless: Successfully deployed the following functions in "dev" to the following regions: Serverless: us-east-1 ------------------------ Serverless: test (kmscreate-test): arn:aws:lambda:us-east-1:<redacted>:function:kmscreate-test:dev e { CredentialsError: Missing credentials in config at Object.parse (native) at /Users/mfuller/node_modules/aws-sdk/lib/metadata_service.js:115:38 at IncomingMessage.<anonymous> (/Users/mfuller/node_modules/aws-sdk/lib/metadata_service.js:74:45) at emitNone (events.js:91:20) at IncomingMessage.emit (events.js:185:7) at endReadableNT (_stream_readable.js:926:12) at _combinedTickCallback (internal/process/next_tick.js:74:11) at process._tickDomainCallback (internal/process/next_tick.js:122:9) message: 'Missing credentials in config', code: 'CredentialsError', time: 2016-07-13T05:41:34.643Z, originalError: { message: 'Could not load credentials from any providers', code: 'CredentialsError', time: 2016-07-13T05:41:34.643Z, originalError: { message: 'Unexpected token < in JSON at position 0' } } } Serverless: error in creating alerts ``` I will get one of my colleagues to try and reproduce.

Posnet

I am also able to reproduce this error using the steps @mfulleratlassian provided. ``` ▶ cd src/test/; sls function deploy -s dev -r us-east-1 Serverless: Deploying the specified functions in "dev" to the following regions: us-east-1 Serverless: ------------------------ Serverless: Successfully deployed the following functions in "dev" to the following regions: Serverless: us-east-1 ------------------------ Serverless: test (serverless-s1ybw8-test): arn:aws:lambda:us-east-1:<redacted>:function:serverless-s1ybw8-test:dev e { Error: connect EHOSTUNREACH 169.254.169.254:80 at Object.exports._errnoException (util.js:1007:11) at exports._exceptionWithHostPort (util.js:1030:20) at TCPConnectWrap.afterConnect [as oncomplete] (net.js:1080:14) cause: { Error: connect EHOSTUNREACH 169.254.169.254:80 at Object.exports._errnoException (util.js:1007:11) at exports._exceptionWithHostPort (util.js:1030:20) at TCPConnectWrap.afterConnect [as oncomplete] (net.js:1080:14) message: 'Missing credentials in config', code: 'CredentialsError', errno: 'EHOSTUNREACH', syscall: 'connect', address: '169.254.169.254', port: 80, time: 2016-07-13T05:57:31.613Z, originalError: { message: 'Could not load credentials from any providers', code: 'CredentialsError', errno: 'EHOSTUNREACH', syscall: 'connect', address: '169.254.169.254', port: 80, time: 2016-07-13T05:57:31.613Z, originalError: [Object] } }, isOperational: true, code: 'CredentialsError', errno: 'EHOSTUNREACH', syscall: 'connect', address: '169.254.169.254', port: 80, time: 2016-07-13T05:57:31.613Z, originalError: { message: 'Could not load credentials from any providers', code: 'CredentialsError', errno: 'EHOSTUNREACH', syscall: 'connect', address: '169.254.169.254', port: 80, time: 2016-07-13T05:57:31.613Z, originalError: { code: 'EHOSTUNREACH', errno: 'EHOSTUNREACH', syscall: 'connect', address: '169.254.169.254', port: 80, message: 'connect EHOSTUNREACH 169.254.169.254:80' } } } Serverless: error in creating alerts ```

martinlindenberg

Well - this looks absolutely strange to me. I am pretty sure that this plugin is able to use the right credentials, as i am using different credentials for different staging environments. The plugin uses the default Serverless aws provider to find the credentials: https://github.com/martinlindenberg/serverless-plugin-alerting/blob/0.5.11/index.js#L302 To reproduce your error I created a new test project as described in your comment https://github.com/martinlindenberg/serverless-plugin-alerting/issues/16#issuecomment-232261890 and changed my .aws/credentials to have no valid credentials for the used profile admin.env ``` AWS_DEV_PROFILE=training AWS_PROD_PROFILE=training ``` edit .aws/credentials to have no `training` profile ``` [training_not_used] aws_access_key_id = <redacted> aws_secret_access_key = <redacted> ``` The output shows, that even the deployment of the function fails `Cant find AWS credentials` ``` mlindenberg@LNX-0010:~/work/ping/pong$ sls_0.5.3 function deploy Serverless: Deploying the specified functions in "dev" to the following regions: eu-west-1 Serverless: ------------------------ Serverless: Failed to deploy the following functions in "dev" to the following regions: Serverless: eu-west-1 ------------------------ Serverless: pong: Cant find AWS credentials ... trace ... ``` Can you please tell my exactly what you changed to create the error? Renaming the profile in .aws/credentials didnt bring your errors.

mfulleratlassian

I am using Serverless 0.5.6 if that has any impact. My setup is exactly as described in my comment.

martinlindenberg

I think i found the reason for that issue: https://github.com/martinlindenberg/serverless-plugin-alerting/blob/0.5.11/index.js#L302 This line returns a promise that needs to be resolved before using it in the following lines https://github.com/martinlindenberg/serverless-plugin-alerting/blob/0.5.11/index.js#L306 In default cases it might work very fast, but when aws needs to search for the credentials with that CredentialProviderChain, it might take longer and throw errors... Options to solve that issue: 1. Use promises to wait for the credentials to be resolved, as in the sns plugin https://github.com/martinlindenberg/serverless-plugin-sns/blob/master/index.js#L283 2. use the internal aws.request method, which solves the credentials automatically. this also removes the requirement of handling the credentials in the plugin. Fixed with Option 2

mfulleratlassian

Thanks @martinlindenberg love your work.