-
Notifications
You must be signed in to change notification settings - Fork 112
JAVA: Add IAM authentication support for ElastiCache/MemoryDB #4891
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
affonsov
wants to merge
6
commits into
main
Choose a base branch
from
java/affonso-iam-connection
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
- Add IamAuthConfig and ServiceType for IAM configuration - Update ServerCredentials to support both password and IAM auth modes - Add refreshIamToken() method to BaseClient for manual token refresh - Prevent updateConnectionPassword() when using IAM authentication - Add native bridge method for IAM token refresh - Update ConnectionManager to handle IAM credentials in protobuf - Add unit tests for ServerCredentials validation Breaking changes: - ServerCredentials.password is no longer @nonnull (supports IAM mode) - Password and IAM config are mutually exclusive Signed-off-by: affonsov <[email protected]>
alexr-bq
approved these changes
Oct 21, 2025
jduo
reviewed
Oct 22, 2025
currantw
reviewed
Oct 22, 2025
java/client/src/main/java/glide/managers/ConnectionManager.java
Outdated
Show resolved
Hide resolved
Co-authored-by: Taylor Curran <[email protected]> Signed-off-by: affonsov <[email protected]>
jduo
approved these changes
Oct 22, 2025
fixed documentatoin refactored refreshItervalSeconds to be similar to the other clients Signed-off-by: affonsov <[email protected]>
Signed-off-by: affonsov <[email protected]>
Signed-off-by: affonsov <[email protected]>
yipin-chen
approved these changes
Oct 22, 2025
currantw
reviewed
Oct 23, 2025
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me! 🎉
Thanks for addressing my comments.
Signed-off-by: affonsov <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overview
This PR adds support for AWS IAM authentication to the Java client, enabling secure connections to ElastiCache and MemoryDB clusters without managing passwords.
Changes
New Classes
IamAuthConfig
: Configuration for IAM authentication with cluster name, service type, region, and optional refresh intervalServiceType
: Enum for ElastiCache and MemoryDB service typesModified Classes
ServerCredentials
password
field (and optionalusername
)username
(required) andiamConfig
password
field is no longer@NonNull
to support IAM modeBaseClient
refreshIamToken()
method for manual IAM token refreshupdateConnectionPassword()
methods to throwConfigurationError
when IAM auth is enabledConnectionManager
updatePassword()
to skip updates when using IAM authenticationgetCredentials()
accessor for credential validationNative Bridge
refreshIamToken()
JNI method inGlideNativeBridge
GlideCoreClient
with proper error handlingCommandManager
submitRefreshIamToken()
method to handle IAM token refresh requestsBreaking changes:
Integration tests
Issue link
This Pull Request is linked to issue (URL): #4498
Checklist
Before submitting the PR make sure the following are checked: