Skip to content

fix: distinguish between wrong and no earthdata credentials - #162

Merged
maxrjones merged 4 commits into
mainfrom
fix/earthdata-secret-login-errors
Sep 30, 2026
Merged

maxrjones merged 4 commits into
mainfrom
fix/earthdata-secret-login-errors

Conversation

@maxrjones

Copy link
Copy Markdown
Member

Summary

This PR makes the failed login error surface on all requests that fail during a given 60s backoff window, rather than falling back to a generic unavailable login strategy.

This fixes an issue that surfaced in VEDA testing and made debugging more challenging than necessary.

Testing

  • Added a local test for the new warning

PR checks

  • Standard CI runs automatically on each push.
  • To run the CDK synth check, add the run-cdk-checks label to this PR.
  • If you push more commits after that run completes, remove and re-add the label to run it again.
  • To trigger a dev deployment, add the deploy-dev label. It smoke-tests tiles from the native MUR, virtual MUR, and virtual NLDAS Icechunk stores after deployment.

A username/password earthdata secret that Earthdata Login refused
surfaced as "failed to establish an Earthdata Login identity" on the
first request, and every request in the following 60s backoff window
fell through to earthaccess-auth's generic "no non-interactive EDL login
strategy available: set EARTHDATA_TOKEN ..." message, which reads as if
no credentials were configured at all.

- Catch LoginAttemptFailure separately when logging in with the secret
  and say that Earthdata Login did not accept the secret's
  EARTHDATA_USERNAME/EARTHDATA_PASSWORD. EDL's response body still goes
  to the service log only.
- Remember a failed first load's sanitized message and re-raise it for
  requests inside its backoff window, so a secret that is missing keys,
  unreadable, or rejected keeps reporting that specific cause.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions github-actions Bot added the fix label Sep 29, 2026
@maxrjones
maxrjones requested a review from hrodmn September 29, 2026 21:40
@maxrjones maxrjones changed the title fix: report why the earthdata secret failed to log in fix: distinguish between wrong and no earthdata credentials Sep 30, 2026
maxrjones and others added 2 commits September 30, 2026 00:34
The module docstring and _secret_arn_unless_latched described the rule
in one dash-laden sentence that was hard to parse. Replace it with the
three cases, in order: secret loads, secret unreachable, no ARN
configured. State why the secret wins even when the environment already
holds a working identity: otherwise the secret is never read and
rotation has no effect until a restart.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The docstring described first-load and refresh failures in two long
sentences joined by dashes, and left out the case where a failed first
fetch falls back to an identity already in the environment. Split it
into the three failure cases the code actually handles and state the
fallback explicitly. Reword the Raises entry and the nothing-to-fall-
back-to comment in _on_fetch_failure to match.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>

@hrodmn hrodmn left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for adding the additional guardrails here - I am looking forward to the day where we can delegate EDL credential management to an external service!

@maxrjones
maxrjones merged commit 1a78ff8 into main Sep 30, 2026
10 checks passed
@maxrjones
maxrjones deleted the fix/earthdata-secret-login-errors branch September 30, 2026 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants