This is an automated email from the ASF dual-hosted git repository.

shahar1 pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/airflow.git


The following commit(s) were added to refs/heads/main by this push:
     new 4b0cbb1c944 Keep the AWS no-credentials tests hermetic on EC2 and 
developer hosts (#73707)
4b0cbb1c944 is described below

commit 4b0cbb1c9441587476bcf412a91345ff3874163b
Author: Shahar Epstein <[email protected]>
AuthorDate: Fri Sep 25 11:44:45 2026 +0300

    Keep the AWS no-credentials tests hermetic on EC2 and developer hosts 
(#73707)
    
    The two tests that exercise the "no credentials" path only cleared the
    credential environment variables, so boto's default chain kept walking:
    on an EC2 host it reaches the instance role through IMDS and finds
    credentials, and the S3 filesystem test additionally wiped the autouse
    fixture's empty AWS_CONFIG_FILE / AWS_SHARED_CREDENTIALS_FILE, so it read
    the developer's ~/.aws instead. Both then fail with credentials found.
---
 providers/amazon/tests/unit/amazon/aws/fs/test_s3.py     | 16 +++++++++++-----
 .../amazon/tests/unit/amazon/aws/hooks/test_base_aws.py  |  2 ++
 2 files changed, 13 insertions(+), 5 deletions(-)

diff --git a/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py 
b/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
index ec633c3c792..1f625b427cf 100644
--- a/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
+++ b/providers/amazon/tests/unit/amazon/aws/fs/test_s3.py
@@ -16,7 +16,6 @@
 # under the License.
 from __future__ import annotations
 
-import os
 from typing import TYPE_CHECKING, cast
 from unittest.mock import patch
 
@@ -59,10 +58,17 @@ class TestFilesystem:
     def test_get_s3fs_anonymous(self, s3fs, monkeypatch):
         from airflow.providers.amazon.aws.fs.s3 import get_fs
 
-        # remove all AWS_* env vars
-        for env_name in os.environ:
-            if env_name.startswith("AWS"):
-                monkeypatch.delenv(env_name, raising=False)
+        # Drop only the credentials: the autouse fixture's empty 
AWS_CONFIG_FILE /
+        # AWS_SHARED_CREDENTIALS_FILE must stay so the chain cannot fall back 
to ~/.aws, and
+        # on an EC2 host it would otherwise reach the instance role via IMDS.
+        for env_name in (
+            "AWS_ACCESS_KEY_ID",
+            "AWS_SECRET_ACCESS_KEY",
+            "AWS_SESSION_TOKEN",
+            "AWS_SECURITY_TOKEN",
+        ):
+            monkeypatch.delenv(env_name, raising=False)
+        monkeypatch.setenv("AWS_EC2_METADATA_DISABLED", "true")
 
         get_fs(conn_id=None, storage_options=None)
 
diff --git a/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py 
b/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
index be68d99af99..d91cba0d3e7 100644
--- a/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
+++ b/providers/amazon/tests/unit/amazon/aws/hooks/test_base_aws.py
@@ -1197,6 +1197,8 @@ def 
test_raise_no_creds_default_credentials_strategy(tmp_path_factory, monkeypat
     for env_key in ("AWS_ACCESS_KEY_ID", "AWS_SECRET_ACCESS_KEY", 
"AWS_SESSION_TOKEN", "AWS_SECURITY_TOKEN"):
         # Delete aws credentials environment variables
         monkeypatch.delenv(env_key, raising=False)
+    # On an EC2 host the credential chain would otherwise reach the instance 
role via IMDS
+    monkeypatch.setenv("AWS_EC2_METADATA_DISABLED", "true")
 
     hook = AwsBaseHook(aws_conn_id=None, client_type="sts")
     with pytest.raises(NoCredentialsError) as credential_error:

Reply via email to