{"repo":"anomalizer/ngx_aws_auth","free":true,"listed":false,"github":"https://github.com/anomalizer/ngx_aws_auth","clone":"git clone https://github.com/anomalizer/ngx_aws_auth.git","description":"nginx module to proxy to authenticated AWS services","language":"C","stars":475,"topics":["nginx","aws-s3"],"license":"BSD-2-Clause","category":"auth-billing-email","readme_excerpt":"AWS proxy module This nginx module can proxy requests to authenticated S3 backends using Amazon's V4 authentication API. The first version of this module was written for the V2 authentication protocol and can be found in the AuthV2 branch. License This project uses the same license as ngnix does i.e. the 2 clause BSD / simplified BSD / FreeBSD license Usage example Implements proxying of authenticated requests to S3. Security considerations The V4 protocol does not need access to the actual secret keys that one obtains from the IAM service. The correct way to use the IAM key is to actually generate a scoped signing key and use this signing key to access S3. This nginx module requires the signing key and not the actual secret key. It is an insecure practise to let the secret key reside on your nginx server. Note that signing keys have a validity of just one week. Hence, they need to be refreshed constantly. Please useyour favourite configuration management system such as saltstack, puppet, chef, etc. etc. to distribute the signing keys to your nginx clusters. Do not forget to HUP the server after placing the new signing key as nginx reads the configuration only at startup time. A standalone python script has been provided to generate the signing key Supported environments This plugin is tested against a variety of nginx versions, compilers, OS versions and hardware architectures. Take a look at the .travis.yml file or the latest travis build status to see the versions that the","default_branch":null,"files":null,"tree":[],"storefront":"/r/anomalizer","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/anomalizer/ngx_aws_auth/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}