Skip to content

feat: add assume-role-arn flag for Entra ID - #915

Merged
Gearheads merged 2 commits into
fidelity:mainfrom
fidelity-contributions:feature/fix-assume-role
Sep 18, 2026
Merged

Gearheads merged 2 commits into
fidelity:mainfrom
fidelity-contributions:feature/fix-assume-role

Conversation

@Gearheads

Copy link
Copy Markdown
Collaborator

What this PR does / why we need it:
This PR will add the --assume-role-arn flag to the Entra ID protocol for the EKS provider to allow users to assume another AWS IAM role in another AWS account.

This is required by some teams that use a global AWS IAM role to reduce the number of AD groups required.

This PR also includes a couple improvements:

  1. Entra ID protocol connection now displays "Time Left" in "kconnect ls" command, similarly to SAML protocol connections
  2. make lint instruction is fixed by upgrading github.com/golangci/golangci-lint/v2 from v2.12.2 to v2.13.2, and resolving out dated dependencies

Which issue(s) this PR fixes (optional, in fixes #<issue number>(, fixes #<issue_number>, ...) format, will close the issue(s) when PR gets merged):
Fixes # Users not able to assume an AWS IAM role with the Entra ID protocol, similarly like they do with the SAML protocol.

Testing

I was able to build kconnect locally, and test the --assume-role-arn flag for Entra ID successfully:

% ./kconnect use eks --namespace cluster-addons --username a637522@fmr.com --password <password> --role-arn arn:aws:iam::716316695455:role/EKS_PlatformReadOnly --assume-role-arn arn:aws:iam::533267081281:role/EKS_PlatformReadOnly --region us-east-1
info	kconnect - the Kubernetes Connection Manager CLI	{"version": ""}
info	authenticating using Entra ID provider	{"app": "kconnect", "provider": "entraid-oauth"}
info	requesting AWS credentials using web identity token	{"app": "kconnect", "provider": "entraid-oauth"}
info	requesting AWS credentials using assume role	{"app": "kconnect", "provider": "entraid-oauth"}
info	discovering clusters	{"app": "kconnect", "provider": "eks"}
info	discovering EKS clusters	{"app": "kconnect", "provider": "eks"}
? Do you want to set an alias? No
info	Command to reconnect using this alias: kconnect to 	{"app": "kconnect"}
info	setting current context	{"context": "kconnect-56675508@eks-fda-shared-dev-east-1"}
info	kubeconfig updated	{"path": "/Users/a637522/.kube/config"}

Also, I checked that make lint works as expected now:

% make lint
cd hack/tools; go build -tags=tools -o bin/golangci-lint github.com/golangci/golangci-lint/v2/cmd/golangci-lint
hack/tools/bin/golangci-lint run -v
INFO golangci-lint has version 2.13.2 built with go1.26.1 from (unknown, modified: ?, mod sum: "h1:bCyq3E4vo9qwzifjpzJqYndEt7Ncva80qkk8G2B4TXU=") on (unknown) 
INFO [config_reader] Config search paths: [./ /Users/a637522/go/src/github.com/Fidelity-External-Staging/fidelity-kconnect /Users/a637522/go/src/github.com/Fidelity-External-Staging /Users/a637522/go/src/github.com /Users/a637522/go/src /Users/a637522/go /Users/a637522 /Users /] 
INFO [config_reader] Used config file .golangci.yml 
INFO [config_reader] Module name "github.com/fidelity/kconnect" 
INFO [goenv] Read go env for 8.271791ms: map[string]string{"GOCACHE":"/Users/a637522/Library/Caches/go-build", "GOROOT":"/opt/homebrew/Cellar/go/1.26.1/libexec"} 
INFO [lintersdb] Active 43 linters: [arangolint asciicheck bidichk clickhouselint copyloopvar decorder dogsled dupl dupword embeddedstructfieldcheck funcorder gocheckcompilerdirectives gocognit goconst gocyclo godoclint gofmt goheader goimports gomoddirectives gomodguard_v2 goprintffuncname grouper inamedparam ineffassign iotamixing maintidx misspell mnd modernize nakedret nestif nolintlint nosprintfhostport prealloc predeclared promlinter tagalign testableexamples testpackage unqueryvet usestdlibvars wsl_v5] 
INFO [loader] Go packages loading at mode 8767 (compiled_files|deps|files|exports_file|imports|name|types_sizes) took 820.612042ms 
INFO [runner/filename_unadjuster] Pre-built 0 adjustments in 9.219166ms 
INFO [linters_context/goanalysis] analyzers took 43.26477615s with top 10 stages: goimports: 37.179572164s, newexpr: 1.127944391s, dupl: 845.418706ms, unqueryvet: 498.378581ms, gofmt: 273.658417ms, goconst: 251.764086ms, misspell: 228.913124ms, ineffassign: 175.917167ms, gomodguard_v2: 171.090914ms, typeindex: 147.065835ms 
INFO [runner/exclusion_paths] Skipped 4 issues by pattern ".*_mock\\.go" 
INFO [runner/exclusion_paths] Skipped 0 issues by pattern "third_party/*" 
INFO [runner/exclusion_paths] Skipped 28 issues by pattern "pkg/azure/wstrust" 
INFO [runner/exclusion_paths] Skipped 0 issues by pattern "examples" 
INFO [runner/exclusion_paths] Skipped 47 issues by pattern "zz_generated.*\\.go$" 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Path: "examples", Linters: "gofmt, goimports"] 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Text: "should not use dot imports|don't use an underscore in package name", Linters: "golint"] 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Path: "zz_generated.*\\.go$", Linters: "gofmt, goimports"] 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Path: ".*_mock\\.go", Linters: "gofmt, goimports"] 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Path: "third_party/*", Linters: "gofmt, goimports"] 
INFO [runner/exclusion_rules] Skipped 0 issues by rules: [Path: "pkg/azure/wstrust", Linters: "gofmt, goimports"] 
INFO [runner] Issues before processing: 204, after processing: 0 
INFO [runner] Processors filtering stat (in/out): path_absoluter: 204/204, exclusion_rules: 125/125, cgo: 204/204, filename_unadjuster: 204/204, exclusion_paths: 204/125, invalid_issue: 204/204, path_relativity: 204/204, generated_file_filter: 125/125, nolint_filter: 125/0 
INFO [runner] processing took 5.273041ms with stages: generated_file_filter: 2.595084ms, nolint_filter: 1.664125ms, exclusion_rules: 630.917µs, path_relativity: 198.125µs, exclusion_paths: 167.125µs, cgo: 4.459µs, invalid_issue: 3.916µs, filename_unadjuster: 3.832µs, path_absoluter: 2.25µs, sort_results: 959ns, max_same_issues: 583ns, diff: 375ns, fixer: 333ns, path_shortener: 249ns, path_prettifier: 208ns, uniq_by_line: 167ns, max_per_file_from_linter: 125ns, severity-rules: 84ns, source_code: 83ns, max_from_linter: 42ns 
INFO [runner] linters took 12.080340459s with stages: goanalysis_metalinter: 12.075010291s 
0 issues.
INFO File cache stats: 0 entries of total size 0B 
INFO Memory: 131 samples, avg is 824.0MB, max is 1529.6MB 
INFO Execution took 12.920068292s 

This branch can be deleted once it is merged.

Signed-off-by: Casale, Robert <robert.casale@fmr.com>
…to v2.13.2

This change will fix the make lint instruction by upgrading github.com/golangci/golangci-lint/v2 from v2.12.2 to v2.13.2, and fix the ambiguous import message from go mod tidy caused by the monolithic dependency google.golang.org/genproto.

Signed-off-by: Casale, Robert <robert.casale@fmr.com>
@Gearheads
Gearheads merged commit 7193879 into fidelity:main Sep 18, 2026
8 checks passed
@Gearheads
Gearheads deleted the feature/fix-assume-role branch September 18, 2026 13:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants