Skip to main content

Ape AWS KMS: Ape plugin to make transactions through AWS KMS

Project description

Ape AWS KMS

Ape plugin to make transactions through AWS KMS

Dependencies

  • python3 version 3.10 or greater, python3-dev

Installation

via pip

You can install the latest release via pip:

pip install ape-aws

via setuptools

You can clone the repository and use setuptools for the most up-to-date version:

git clone https://github.com/ApeWorX/ape-aws.git
cd ape-aws
python3 setup.py install

Quick Usage

pip install ape-aws

Using CLI tool

List commands:

ape aws -h

See logged in profile (useful for debugging auth in containers)

ape aws whoami

To create a new user (recommended for cloud usage)

ape aws users new USER

To delete this user (WARNING this is permanent)

ape aws users remove USER

Create an access key for this user (WARNING don't lose generated token)

ape aws users tokens new USER > .env.USER

To create a new Ethereum signing key (recommended to generate)

ape aws keys generate KEY

To schedule this signing key for deletion (WARNING takes 30 days)

ape aws keys remove KEY

To grant your user access to the signing key (don't forget to do this!)

ape aws keys grant KEY -u USER

IPython

First, create a KMS key with the CLI tool

ape console
In [1]: kms_signer = accounts.load("KEY")
In [2]: kms_signer.sign_message("12345")
Out[2]: <MessageSignature v=27, r=0x..., s=0x...>

Now to test your new IAM user's access, you can do the following

env $(echo .env.USER | xargs) ape console

and you should be able to do the same as the above!

Use the access token above to run with your containers by supplying them as environment variables

WARNING: Don't forget to cycle your access tokens on a regular basis to prevent access leakage!

Development

This project is in development and should be considered a beta. Things might not be in their final state and breaking changes may occur. Comments, questions, criticisms and pull requests are welcomed.

Prerequisites to AWS Setup

To begin, create a virtual environment set up and activate the virtual environment before doing anything for the setup of AWS

  1. You must have an AWS account
  2. Must be an AWS Identity and Access Management (IAM) user with administrator access
  3. Must have configured AWS credentials
  4. Must have Docker, Python3 and pip installed on your workstation

AWS Setup

For Mac and Linux

Create a ~/.aws folder in your home directory:

mkdir ~/.aws

Note: get your access key and key id from your IAM in you AWS account here. Create a credentials file in the ~/.aws folder:

cat <<EOF > ~/.aws/credentials
[default]
aws_access_key_id = YOUR_ACCESS_KEY
aws_secret_access_key = YOUR_SECRET
EOF

Create a config file in the ~/.aws folder:

cat <<EOF > ~/.aws/config
[default]
region = YOUR_REGION
output = json
EOF

AWS KMS Key Import Steps

For manual setup, follow this article

License

This project is licensed under the Apache 2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ape_aws-0.8.1.tar.gz (26.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ape_aws-0.8.1-py3-none-any.whl (20.1 kB view details)

Uploaded Python 3

File details

Details for the file ape_aws-0.8.1.tar.gz.

File metadata

  • Download URL: ape_aws-0.8.1.tar.gz
  • Upload date:
  • Size: 26.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for ape_aws-0.8.1.tar.gz
Algorithm Hash digest
SHA256 44afa1755c3b38d963b52627d917ef1a7a83cd8dbfae4d110f98f4ec84a77fe2
MD5 7a41eef6c30aa4fb905ce3073e0c5b1d
BLAKE2b-256 4200d1350945fa06815dab52942d420ef718300a67706b053aec9a63d2851b7a

See more details on using hashes here.

Provenance

The following attestation bundles were made for ape_aws-0.8.1.tar.gz:

Publisher: publish.yaml on ApeWorX/ape-aws

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ape_aws-0.8.1-py3-none-any.whl.

File metadata

  • Download URL: ape_aws-0.8.1-py3-none-any.whl
  • Upload date:
  • Size: 20.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for ape_aws-0.8.1-py3-none-any.whl
Algorithm Hash digest
SHA256 bc2b7cde208f42f8e5161fe206c260297369e420a8013aed49e08c379ff93d1d
MD5 74c3d3921745cb6945570d0b9421bafd
BLAKE2b-256 ae6ab8295492adf59c8c473d78e91fa599511fdfb6274fa2bf28fe83be0adc19

See more details on using hashes here.

Provenance

The following attestation bundles were made for ape_aws-0.8.1-py3-none-any.whl:

Publisher: publish.yaml on ApeWorX/ape-aws

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page