Skip to content

Repository files navigation

AWS AOSS Proxy

The AWS AOSS Proxy will sign incoming HTTP requests and forward them to the host specified in the Host header.

You can strip out arbitrary headers from the incoming request by using the -s option.

Getting Started

Build and run the Proxy

The proxy uses the default AWS SDK for Go credential search path:

  • Environment variables.
  • Shared credentials file.
  • IAM role for Amazon EC2 or ECS task role

More information can be found in the developer guide

docker build -t aws-sigv4-proxy .# Env vars
docker run --rm -ti \
-e 'AWS_ACCESS_KEY_ID=<YOUR ACCESS KEY ID>' \
-e 'AWS_SECRET_ACCESS_KEY=<YOUR SECRET ACCESS KEY>' \
-p 8080:8080 \
aws-sigv4-proxy -v
# Shared Credentials
docker run --rm -ti \
-v ~/.aws:/root/.aws \
-p 8080:8080 \
-e 'AWS_SDK_LOAD_CONFIG=true' \
-e 'AWS_PROFILE=<SOME PROFILE>' \
aws-sigv4-proxy -v

Configuration

When running the Proxy, the following flags can be used (none are required) :

Flag (or short form)TypeDescriptionDefault
verbose or vBooleanEnable additional logging, implies all the log-* optionsFalse
log-failed-requestsBooleanLog 4xx and 5xx response bodyFalse
log-signing-processBooleanLog sigv4 signing processFalse
portStringPort to serve http on8080
strip or sStringHeaders to strip from incoming requestNone
role-arnStringAmazon Resource Name (ARN) of the role to assumeNone
nameStringAWS Service to sign forNone
hostStringHost to proxy toNone
regionStringAWS region to sign forNone
no-verify-sslBooleanDisable peer SSL certificate validationFalse
transport.idle-conn-timeoutDurationIdle timeout to the upstream service40s

Examples

Amazon OpenSearch Service (Serverless)

curl -H 'host: <REST_API_ID>.aoss.<AWS_REGION>.amazonaws.com' http://localhost:9200/<PATH>

Running the service with Assume Role to use temporary credentials

docker run --rm -ti \
-v ~/.aws:/root/.aws \
-p 8080:8080 \
-e 'AWS_SDK_LOAD_CONFIG=true' \
-e 'AWS_PROFILE=<SOME PROFILE>' \
aws-aoss-proxy -v --role-arn <ARN OF ROLE TO ASSUME>

Include service name & region overrides when you notice errors like unable to determine service from host for API gateway, for example.

docker run --rm -ti \
-v ~/.aws:/root/.aws \
-p 8080:8080 \
-e 'AWS_SDK_LOAD_CONFIG=true' \
-e 'AWS_PROFILE=<SOME PROFILE>' \
aws-aoss-proxy -v --name execute-api --region us-east-1

Reference

License

This library is licensed under the Apache 2.0 License.

About

This project signs and proxies HTTP requests with Sigv4 to OpenSearch Serverless

Resources

Code of conduct

Contributing

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages