[ 
https://issues.apache.org/jira/browse/NIFI-14927?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18017665#comment-18017665
 ] 

David Handermann commented on NIFI-14927:
-----------------------------------------

It looks like the library does support a number of optional properties that 
could enable configuration of additional credential strategies. This would not 
enable use of the Credentials Provider Service, but should be able to support 
some additional configuration.

[~nicklarsennz] For clarity, you are specifically interested in the option to 
configure the ARN for the Assume Role?

> Make use of AWSCredentialsProviderControllerService for 
> AmazonMSKConnectionService
> ----------------------------------------------------------------------------------
>
>                 Key: NIFI-14927
>                 URL: https://issues.apache.org/jira/browse/NIFI-14927
>             Project: Apache NiFi
>          Issue Type: Improvement
>            Reporter: Nick
>            Priority: Major
>         Attachments: image-2025-09-01-21-50-48-663.png, 
> image-2025-09-01-21-52-34-971.png, image-2025-09-02-11-21-31-147.png
>
>
> Currently, the AmazonMSKConnectionService lacks the authentication settings 
> that are available through the AWSCredentialsProviderControllerService on the 
> other AWS providers (to allow things like Assume Role).
> !image-2025-09-01-21-50-48-663.png|width=614,height=461!
> Currently this means we need to set permissions on the AWS IAM Role that is 
> mapped to the PodIdentity. Instead, we would rather configure each provider 
> with the applicable IAM Role to be assumed from the PodIdentity Role.
> ListS3, AwsSecretsManagerParameterProvider (and others) allow a more 
> versatile and expected configuration using the 
> AWSCredentialsProviderControllerService:
> !image-2025-09-02-11-21-31-147.png|width=649,height=361!
> !image-2025-09-01-21-52-34-971.png|width=647,height=501!
> Can the same be applied to AmazonMSKConnectionService?
>  



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to