This is an automated email from the ASF dual-hosted git repository.
shahar1 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git
The following commit(s) were added to refs/heads/main by this push:
new 4b0cbb1c944 Keep the AWS no-credentials tests hermetic on EC2 and
developer hosts (#73707)
4b0cbb1c944 is described below
commit 4b0cbb1c9441587476bcf412a91345ff3874163b
Author: Shahar Epstein <[email protected]>
AuthorDate: Fri Sep 25 11:44:45 2026 +0300
Keep the AWS no-credentials tests hermetic on EC2 and developer hosts
(#73707)
The two tests that exercise the "no credentials" path only cleared the
credential environment variables, so boto's default chain kept walking:
on an EC2 host it reaches the instance role through IMDS and finds
credentials, and the S3 filesystem test additionally wiped the autouse
fixture's empty AWS_CONFIG_FILE / AWS_SHARED_CREDENTIALS_FILE, so it read
the developer's ~/.aws instead. Both then fail with credentials found.
---
providers/amazon/tests/unit/amazon/aws/fs/test_s3.py | 16 +++++++++++-----
.../amazon/tests/unit/amazon/aws/hooks/test_base_aws.py | 2 ++
2 files changed, 13 insertions(+), 5 deletions(-)
diff --git a/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
b/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
index ec633c3c792..1f625b427cf 100644
--- a/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
+++ b/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
@@ -16,7 +16,6 @@
# under the License.
from __future__ import annotations
-import os
from typing import TYPE_CHECKING, cast
from unittest.mock import patch
@@ -59,10 +58,17 @@ class TestFilesystem:
def test_get_s3fs_anonymous(self, s3fs, monkeypatch):
from airflow.providers.amazon.aws.fs.s3 import get_fs
- # remove all AWS_* env vars
- for env_name in os.environ:
- if env_name.startswith("AWS"):
- monkeypatch.delenv(env_name, raising=False)
+ # Drop only the credentials: the autouse fixture's empty
AWS_CONFIG_FILE /
+ # AWS_SHARED_CREDENTIALS_FILE must stay so the chain cannot fall back
to ~/.aws, and
+ # on an EC2 host it would otherwise reach the instance role via IMDS.
+ for env_name in (
+ "AWS_ACCESS_KEY_ID",
+ "AWS_SECRET_ACCESS_KEY",
+ "AWS_SESSION_TOKEN",
+ "AWS_SECURITY_TOKEN",
+ ):
+ monkeypatch.delenv(env_name, raising=False)
+ monkeypatch.setenv("AWS_EC2_METADATA_DISABLED", "true")
get_fs(conn_id=None, storage_options=None)
diff --git a/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
b/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
index be68d99af99..d91cba0d3e7 100644
--- a/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
+++ b/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
@@ -1197,6 +1197,8 @@ def
test_raise_no_creds_default_credentials_strategy(tmp_path_factory, monkeypat
for env_key in ("AWS_ACCESS_KEY_ID", "AWS_SECRET_ACCESS_KEY",
"AWS_SESSION_TOKEN", "AWS_SECURITY_TOKEN"):
# Delete aws credentials environment variables
monkeypatch.delenv(env_key, raising=False)
+ # On an EC2 host the credential chain would otherwise reach the instance
role via IMDS
+ monkeypatch.setenv("AWS_EC2_METADATA_DISABLED", "true")
hook = AwsBaseHook(aws_conn_id=None, client_type="sts")
with pytest.raises(NoCredentialsError) as credential_error: