Dvc: s3 remote: DVC asks MFA code for each file on push/pull

Created on 14 Nov 2019  路  11Comments  路  Source: iterative/dvc

Most helpful comment

To get the above workaround working, I had to remove the mfa_serial = ... line from the profile I was using in ~/.aws/config

All 11 comments

To get the above workaround working, I had to remove the mfa_serial = ... line from the profile I was using in ~/.aws/config

Might be solved by caching the session https://github.com/iterative/dvc/issues/2473#issuecomment-554191280 , but need to confirm.

Looked it up. This probably won't be solved by threadsafe caching s3 prop. I am surprised MFA work with dvc at all though.

Need to ask the user how MFA device is set.

We could solve it the same way we do it with passphrase-s for ssh, by using ask_password config option, but maybe we could auto-detect this somehow. Need to research this.

From https://docs.aws.amazon.com/cli/latest/topic/config-vars.html

If you specify an mfa_serial, then the first time an AssumeRole call is made, you will be prompted to enter the MFA code. Subsequent commands will use the cached temporary credentials. However, when the temporary credentials expire, you will be re-prompted for another MFA code.

need to take a closer look.

It feels to me that we are not caching some boto session properly, thus preventing it from caching an access token.

@efiop your related lib says it is not needed anymore:

You no longer need this package as of botocore version 1.8.14, which now includes the JSON file cache structure traditionally used by the AWS CLI

Was this page helpful?
0 / 5 - 0 ratings

Related issues

pared picture pared  路  73Comments

shcheklein picture shcheklein  路  36Comments

kskyten picture kskyten  路  44Comments

luchoPipe87 picture luchoPipe87  路  69Comments

dmpetrov picture dmpetrov  路  35Comments