# Artifact uploads using AWS\_WEB\_IDENTITY\_TOKEN\_FILE creates an empty 0kb file in S3 bucket

**URL:** <https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505>\
**Category:** General Discussions\
**Created:** [January 19, 2022, 3:30pm UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505 "2022-01-19T15:30:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![grandfield](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/grandfield/32/949_2.png) [@grandfield](https://hub.mender.io/u/grandfield)\
**Post date:** [January 19, 2022, 3:30pm UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505/1 "2022-01-19T15:30:43Z")

</div>

This is a strange one.

I am testing deployment via mender helm on EKS with OIDC service account roles. This sets up an AWS\_WEB\_IDENTITY\_TOKEN\_FILE environment variable. this role has permission to write to an s3 bucket. I verified this works with AWS CLI, and it is also detected by mender deployment. There are no access denied errors when the deployments executable starts up. The deployments application does have permission to write to the bucket, but when I used mender-ui to upload an artifact, it creates an empty file in the s3 bucket.

If I use AWS access tokens, I have no problem. So to summarize, in side the deployments pod:

**# This creates an empty file on upload**  
`AWS_SDK_LOAD_CONFIG=1 DEPLOYMENTS_AWS_AUTH_SECRET= DEPLOYMENTS_AWS_AUTH_KEY= AWS_WEB_IDENTITY_TOKEN_FILE="/var/run/secrets/eks.amazonaws.com/serviceaccount/token" AWS_ROLE_ARN=arn:aws:iam::123123123123:role/MyS3WritingRole deployments --config /etc/deployments/config.yaml`

**# This works fine**  
`DEPLOYMENTS_AWS_AUTH_SECRET=<MYSECRET> DEPLOYMENTS_AWS_AUTH_KEY=<MYKEY> AWS_WEB_IDENTITY_TOKEN_FILE="" deployments --config /etc/deployments/config.yaml`

There are no details logged by deployments service that give me any further information.

---

<div class="post-metadata">

**Author:** ![grandfield](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/grandfield/32/949_2.png) [@grandfield](https://hub.mender.io/u/grandfield)\
**Post date:** [January 19, 2022, 6:22pm UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505/2 "2022-01-19T18:22:08Z")

</div>

This doesn’t appear to happen on 3.1.0, only on mender-latest. Hold tough on looking into this until I have more detail.

---

<div class="post-metadata">

**Author:** ![grandfield](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/grandfield/32/949_2.png) [@grandfield](https://hub.mender.io/u/grandfield)\
**Post date:** [January 19, 2022, 6:39pm UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505/3 "2022-01-19T18:39:12Z")

</div>

Can confirm that this is only a problem with deployments:mender-master. It works fine with 3.0.0. Apologies for the noise, but hopefully this will help your current development.

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [January 19, 2022, 7:57pm UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505/4 "2022-01-19T19:57:45Z")

</div>

Thanks @grandfield for your report.  
I will create a bug report in our Jira tracking system.

---

<div class="post-metadata">

**Author:** ![grandfield](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/grandfield/32/949_2.png) [@grandfield](https://hub.mender.io/u/grandfield)\
**Post date:** [January 28, 2022, 10:12am UTC](https://hub.mender.io/t/artifact-uploads-using-aws-web-identity-token-file-creates-an-empty-0kb-file-in-s3-bucket/4505/5 "2022-01-28T10:12:41Z")

</div>

just a little more info. This happens on 3.2.0 also, but not on 3.1.0, so it was introduced in that time.
