Skip to main content
Pre-release

This release is a pre-release and may not be stable for production use.

cloud-idaas-akless-alibabacloud-adapter

Python Version License Development Status Version

简体中文 | English

Python SDK for IDaaS (Identity as a Service) AKless Adapter — Enables AK-free authentication for Alibaba Cloud services using IDaaS PAM (Privileged Access Management) to obtain STS temporary credentials.

Features

  • AK-free Authentication: Eliminates the need for long-term AccessKey, uses OIDC Token to obtain STS temporary credentials via IDaaS PAM, reducing the risk of credential leakage
  • Multi-SDK Adaptation: Provides credential provider adapters for multiple Alibaba Cloud SDKs, including OSS V1, OSS V2, and SLS
  • Automatic Credential Refresh: Built-in credential caching and automatic refresh based on expiration time, ensuring seamless credential rotation
  • Simple Integration: Factory class provides one-line creation of credential providers, minimizing integration effort

Requirements

  • Python >= 3.9
  • Dependencies:
    • cloud-idaas-core >= 0.0.5b0
    • alibabacloud-credentials >= 1.0.0
    • oss2 >= 2.18.0
    • alibabacloud-oss-v2 >= 1.0.0
    • aliyun-log-python-sdk >= 0.9.0

Installation

pip install cloud-idaas-akless-alibabacloud-adapter

Prerequisites

This SDK depends on cloud-idaas-core. You need to complete the IDaaS Core SDK initialization before using this adapter.

  1. Install and configure cloud-idaas-core, refer to cloud-idaas-core README for details.

  2. In the configuration file, set the scope to the IDaaS built-in scope for PAM:

    {
        "scope": "urn:cloud:idaas:pam|.all"
    }
    
  3. Complete the IDaaS Core SDK initialization:

    from cloud_idaas.core import IDaaSCredentialProviderFactory
    
    IDaaSCredentialProviderFactory.init()
    

Quick Start

The simplest way to use this SDK is through the IDaaSPamAklessCredentialFactory factory class:

from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.alibabacloud.pam import IDaaSPamAklessCredentialFactory

# 1. Initialize IDaaS Core SDK
IDaaSCredentialProviderFactory.init()

# 2. Create an Alibaba Cloud credentials provider
credentials_provider = IDaaSPamAklessCredentialFactory.get_alibaba_cloud_credentials_provider(
    role_arn="acs:ram::123456789:role/your-role-name"
)

# 3. Get credentials
credentials = credentials_provider.get_credentials()
print(credentials.access_key_id)
print(credentials.access_key_secret)
print(credentials.security_token)

Note: The role_arn parameter can also be configured via the environment variable ALIBABA_CLOUD_ROLE_ARN.

Usage Examples

OSS V1 (oss2)

import oss2
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.alibabacloud.pam import IDaaSPamAklessCredentialFactory

# Initialize
IDaaSCredentialProviderFactory.init()

# Create OSS V1 credentials provider
oss_v1_provider = IDaaSPamAklessCredentialFactory.get_oss_v1_credential_provider(
    role_arn="acs:ram::123456789:role/your-role-name"
)

# Use with OSS V1 SDK
auth = oss2.ProviderAuthV4(oss_v1_provider)
bucket = oss2.Bucket(auth, "https://oss-cn-hangzhou.aliyuncs.com", "your-bucket-name")

OSS V2 (alibabacloud-oss-v2)

import alibabacloud_oss_v2 as oss
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.alibabacloud.pam import IDaaSPamAklessCredentialFactory

# Initialize
IDaaSCredentialProviderFactory.init()

# Create OSS V2 credentials provider
oss_v2_provider = IDaaSPamAklessCredentialFactory.get_oss_v2_credential_provider(
    role_arn="acs:ram::123456789:role/your-role-name"
)

# Use with OSS V2 SDK
cfg = oss.config.load_default()
cfg.credentials_provider = oss_v2_provider
cfg.region = "cn-hangzhou"
client = oss.Client(cfg)

SLS (aliyun-log-python-sdk)

from aliyun.log import LogClient
from cloud_idaas.core import IDaaSCredentialProviderFactory
from cloud_idaas.adapter.alibabacloud.pam import IDaaSPamAklessCredentialFactory

# Initialize
IDaaSCredentialProviderFactory.init()

# Create SLS credentials provider
sls_provider = IDaaSPamAklessCredentialFactory.get_sls_credential_provider(
    role_arn="acs:ram::123456789:role/your-role-name"
)

# Use with SLS SDK
client = LogClient("cn-hangzhou.log.aliyuncs.com", credentials_provider=sls_provider)

API Reference

IDaaSPamAklessCredentialFactory

Factory class providing static methods to create credential providers.

Method Return Type Description
get_alibaba_cloud_credentials_provider(role_arn=None) IDaaSPamAlibabaCloudCredentialsProvider Creates a general Alibaba Cloud credentials provider
get_oss_v1_credential_provider(role_arn=None) IDaaSPamOSSV1CredentialsProvider Creates an OSS V1 SDK credentials provider
get_oss_v2_credential_provider(role_arn=None) IDaaSPamOSSV2CredentialsProvider Creates an OSS V2 SDK credentials provider
get_sls_credential_provider(role_arn=None) IDaaSPamSLSCredentialsProvider Creates an SLS SDK credentials provider

IDaaSPamAlibabaCloudCredentialsProvider

Core credentials provider that obtains STS temporary credentials from PAM API using OIDC Token.

Parameter Type Required Default Description
developer_api_endpoint str Yes - PAM Developer API endpoint
idaas_instance_id str Yes - IDaaS instance ID
role_arn str No Env ALIBABA_CLOUD_ROLE_ARN RAM role ARN to assume
duration_seconds int No 3600 Session duration in seconds (minimum 900)
connect_timeout int No 5000 Connection timeout in milliseconds
read_timeout int No 10000 Read timeout in milliseconds

Environment Variables

Variable Description
ALIBABA_CLOUD_ROLE_ARN RAM role ARN. Used when role_arn is not explicitly provided
ALIBABA_CLOUD_OIDC_TOKEN_FILE Path to the OIDC Token file. Used for OIDC Token provider

Support and Feedback

License

This project is licensed under the Apache License 2.0.

Release files for cloud-idaas-akless-alibabacloud-adapter 0.0.1b0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cloud-idaas-akless-alibabacloud-adapter 0.0.1b0
File Size Uploaded
cloud_idaas_akless_alibabacloud_adapter-0.0.1b0.tar.gz 17.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cloud-idaas-akless-alibabacloud-adapter 0.0.1b0
File Interpreter ABI Platform
cloud_idaas_akless_alibabacloud_adapter-0.0.1b0-py3-none-any.whl Python 3 none any Details

Total release size: 34.0 kB

Release files / cloud_idaas_akless_alibabacloud_adapter-0.0.1b0.tar.gz

Download URL cloud_idaas_akless_alibabacloud_adapter-0.0.1b0.tar.gz
Size 17.9 kB
Tags Source
SHA-256 checksum
How to use checksums
4fa9ebcf75329ec70fc22a99ea37db4b912da3e0b8966916d8c4fb9ee4bd0ce9
BLAKE2b-256 checksum
How to use checksums
4c2cd1202087241240b1fc71ea30265eac1cabc9b95e92973349f55baaa6a055
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 16, 2026.

Transparency log

Release files / cloud_idaas_akless_alibabacloud_adapter-0.0.1b0-py3-none-any.whl

Download URL cloud_idaas_akless_alibabacloud_adapter-0.0.1b0-py3-none-any.whl
Size 16.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b870bb761f264f07d4f22218491ebd07402c6f5b7a2d0bbbc5437b3a2dd236a9
BLAKE2b-256 checksum
How to use checksums
a965f13fd3cdac891b06595f49a26d0e5af039540e28d4f7bf0eb2a2a9db7668
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 16, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.0.1b0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page