Skip to main content

Ape AWS KMS: Ape plugin to make transactions through AWS KMS

Project description

Ape AWS KMS

Ape plugin to make transactions through AWS KMS

Dependencies

  • python3 version 3.10 or greater, python3-dev

Installation

via pip

You can install the latest release via pip:

pip install ape-aws

via setuptools

You can clone the repository and use setuptools for the most up-to-date version:

git clone https://github.com/ApeWorX/ape-aws.git
cd ape-aws
python3 setup.py install

Quick Usage

pip install ape-aws

Using CLI tool

List commands:

ape aws -h

See logged in profile (useful for debugging auth in containers)

ape aws whoami

To create a new user (recommended for cloud usage)

ape aws users new USER

To delete this user (WARNING this is permanent)

ape aws users remove USER

Create an access key for this user (WARNING don't lose generated token)

ape aws users tokens new USER > .env.USER

To create a new Ethereum signing key (recommended to generate)

ape aws keys generate KEY

To schedule this signing key for deletion (WARNING takes 30 days)

ape aws keys remove KEY

To grant your user access to the signing key (don't forget to do this!)

ape aws keys grant KEY -u USER

IPython

First, create a KMS key with the CLI tool

ape console
In [1]: kms_signer = accounts.load("KEY")
In [2]: kms_signer.sign_message("12345")
Out[2]: <MessageSignature v=27, r=0x..., s=0x...>

Now to test your new IAM user's access, you can do the following

env $(echo .env.USER | xargs) ape console

and you should be able to do the same as the above!

Use the access token above to run with your containers by supplying them as environment variables

WARNING: Don't forget to cycle your access tokens on a regular basis to prevent access leakage!

Development

This project is in development and should be considered a beta. Things might not be in their final state and breaking changes may occur. Comments, questions, criticisms and pull requests are welcomed.

Prerequisites to AWS Setup

To begin, create a virtual environment set up and activate the virtual environment before doing anything for the setup of AWS

  1. You must have an AWS account
  2. Must be an AWS Identity and Access Management (IAM) user with administrator access
  3. Must have configured AWS credentials
  4. Must have Docker, Python3 and pip installed on your workstation

AWS Setup

For Mac and Linux

Create a ~/.aws folder in your home directory:

mkdir ~/.aws

Note: get your access key and key id from your IAM in you AWS account here. Create a credentials file in the ~/.aws folder:

cat <<EOF > ~/.aws/credentials
[default]
aws_access_key_id = YOUR_ACCESS_KEY
aws_secret_access_key = YOUR_SECRET
EOF

Create a config file in the ~/.aws folder:

cat <<EOF > ~/.aws/config
[default]
region = YOUR_REGION
output = json
EOF

AWS KMS Key Import Steps

For manual setup, follow this article

License

This project is licensed under the Apache 2.0.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ape_aws-0.8.2.tar.gz (26.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ape_aws-0.8.2-py3-none-any.whl (20.1 kB view details)

Uploaded Python 3

File details

Details for the file ape_aws-0.8.2.tar.gz.

File metadata

  • Download URL: ape_aws-0.8.2.tar.gz
  • Upload date:
  • Size: 26.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for ape_aws-0.8.2.tar.gz
Algorithm Hash digest
SHA256 568cf20bc44ed6c3a453871206bfe1480fc4cff467bfb7923c0135e253f64c7e
MD5 df772490eee9a0a2737c8e11b62315e4
BLAKE2b-256 40cd1a39763e8b4aaad67777c286ff1a93a4f8a65769b0f368f7a76b62d8b940

See more details on using hashes here.

Provenance

The following attestation bundles were made for ape_aws-0.8.2.tar.gz:

Publisher: publish.yaml on ApeWorX/ape-aws

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file ape_aws-0.8.2-py3-none-any.whl.

File metadata

  • Download URL: ape_aws-0.8.2-py3-none-any.whl
  • Upload date:
  • Size: 20.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.12.9

File hashes

Hashes for ape_aws-0.8.2-py3-none-any.whl
Algorithm Hash digest
SHA256 8c5a59393f68be70d49562ac7230d58cb6bcfdc778094fde3e2e5e9607fdf483
MD5 248044ddf294a0fb9988ae464a723a47
BLAKE2b-256 14fbd5a277755c6a677883071ef3ca69ea35f4e3356908355ab117d722bc11f1

See more details on using hashes here.

Provenance

The following attestation bundles were made for ape_aws-0.8.2-py3-none-any.whl:

Publisher: publish.yaml on ApeWorX/ape-aws

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page