# Credential\_process support for AWS CloudWatch plugin

**URL:** <https://community.influxdata.com/t/credential-process-support-for-aws-cloudwatch-plugin/18251>\
**Category:** Systems\
**Tags:** telegraf\
**Created:** [February 9, 2021, 2:13am UTC](https://community.influxdata.com/t/credential-process-support-for-aws-cloudwatch-plugin/18251 "2021-02-09T02:13:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kpv](https://avatars.discourse-cdn.com/v4/letter/k/45deac/32.png) [@kpv](https://community.influxdata.com/u/kpv)\
**Post date:** [February 9, 2021, 2:13am UTC](https://community.influxdata.com/t/credential-process-support-for-aws-cloudwatch-plugin/18251/1 "2021-02-09T02:13:44Z")

</div>

Hi all,

I am trying to configure Cloduwatch output plugin credentials via credential Process [AWS SDKs and Tools](https://docs.aws.amazon.com/credref/latest/refdocs/setting-global-credential_process.html)  
I have added following to **~/.aws/config file**

[default]  
credential\_process = /root/decrypt.sh /root/key.json.enc

The intention is to use a custom decrypt script to provide the access key/secret key.  
For some reason this doesn’t seem to work and report ‘no valid providers in chain’. Is there anything on telegraf code which might be preventing this ?

key is encrypted and following script is used to decrypt it.  
$ /root/decrypt.sh /root/key.json.enc  
{  
“Version”: 1,  
“AccessKeyId”: “XXXXX”,  
“SecretAccessKey”: “XXXXX”  
“SessionToken”: “”  
}

PS: adding access key/secret key directly to ‘.awg/config’ seems to work. i.e paths seems to be rightly picked. Looks like the executable pointed by credential\_process fails to get executed from the config.

Any input much appreciated.

Advance Thanks  
-KP

---

<div class="post-metadata">

**Author:** ![sspaink](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/sspaink/32/6402_2.png) [@sspaink](https://community.influxdata.com/u/sspaink)\
**Post date:** [February 19, 2021, 10:13pm UTC](https://community.influxdata.com/t/credential-process-support-for-aws-cloudwatch-plugin/18251/2 "2021-02-19T22:13:06Z")

</div>

Looking over the code that processes the AWS credentials, it seems Telegraf doesn’t support `credential_process` at the moment. The source code in question: [https://github.com/influxdata/telegraf/blob/master/config/aws/credentials.go](https://github.com/influxdata/telegraf/blob/master/config/aws/credentials.go). Can you open up a issue in the Telegraf repository requesting this feature? Thanks! Pull requests are definitely welcome if you would like to add it yourself 🙂

For more info on the current supported credentials configurations are listed in the README: [telegraf/plugins/inputs/cloudwatch at master · influxdata/telegraf · GitHub](https://github.com/influxdata/telegraf/tree/master/plugins/inputs/cloudwatch#amazon-authentication)

---

<div class="post-metadata">

**Author:** ![kpv](https://avatars.discourse-cdn.com/v4/letter/k/45deac/32.png) [@kpv](https://community.influxdata.com/u/kpv)\
**Post date:** [February 20, 2021, 1:02am UTC](https://community.influxdata.com/t/credential-process-support-for-aws-cloudwatch-plugin/18251/3 "2021-02-20T01:02:00Z")

</div>

Thanks for the reply.  
I believe an additional support isn’t required. It should work the same way it works when I place the credentials in ~/.aws/credentials or ~/.aws/config. right?

Only difference is when you set credential\_process the credentials is made available in STDOUT. Just wondering if telegraf fails to/or prevent it-selves from reading those from STOUT? Just a thought.Can this be the case?
