aws-stash
An attempt to make AWS SSM Parameter Store interaction easier and exploit its full potential.
Several tools like chamber are already available to provide applications with secrets and other configuration values stored in AWS SSM Parameter Store as environment variables, but they were missing some handy features and flexible output formats, and I was struggling to find any that would also be able to set them.
Usage
$ aws-stash --help
usage: aws-stash [-h] [-p PARAMS [PARAMS ...]] [-w [WRITE]] [-m] [-f]
[-d DESCRIPTION] [-k KMS] [-c] [-o {text,json,export}] [-l]
[-r] [--delete] [-q] [--full] [-v]
path
positional arguments:
path Path to the parameter key or folder containing
parameter keys
optional arguments:
-h, --help show this help message and exit
-p PARAMS [PARAMS ...], --params PARAMS [PARAMS ...]
Parameter keys
-w [WRITE], --write [WRITE]
Write parameter value, leave it empty to input it from
STDIN
-m, --multi-line Accept multi-line value from STDIN, end input with
CTRL+D
-f, --force Force overwrite existing value
-d DESCRIPTION, --description DESCRIPTION
Add a description to the parameter
-k KMS, --kms KMS KMS key alias to encrypt the value
-c, --copy Copy value to the clipboard instead of showing it
-o {text,json,export}, --output {text,json,export}
Output format
-l, --list List all paramaters under same level path
-r, --recursive Process all paramaters recursively starting from path
--delete Delete a single parameter or all parameters
recursively starting from path if using --recurise
-q, --quiet Output only the values of the parameters
--full Output fully qualified parameter path
-v, --verbose Output parameters details
AWS credentials
This tool combines nicely with aws-vault to provide AWS credentials in a more secure and convenient way than storing them in ~/.aws/credentials files.
List keys recursively
$ aws-vault exec my-aws-profile -- aws-stash -r -l /
/dev/
/dev/application-bar/
/dev/application-bar/ENV_VAR_XXX
/dev/application-bar/SECRET_YYY
/dev/application-foo/
/dev/application-foo/ENV_VAR_XXX
/staging/
/staging/application-bar/
/staging/application-bar/ENV_VAR_XXX
/staging/application-bar/SECRET_YYY
/staging/application-foo/
/staging/application-foo/ENV_VAR_ZZZ
Installation from source
git clone https://github.com/askainet/aws-stash
pip install aws-stash/
Release files for aws-stash 0.0.9
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aws-stash-0.0.9.tar.gz | 7.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aws_stash-0.0.9-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 15.6 kB
Release files / aws-stash-0.0.9.tar.gz
| Download URL | aws-stash-0.0.9.tar.gz |
|---|---|
| Size | 7.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f03136e0e24ebdcc0a29cc5b0907cc6eef016d7b68f826dedfda4c63cc8fc2dc
|
|
BLAKE2b-256 checksum How to use checksums |
7566faa331c0b18b360f857cd9f56b2a0c717fa5948d285695185fa88d601d31
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.6.0 requests/2.24.0 setuptools/40.6.2 requests-toolbelt/0.9.1 tqdm/4.50.2 CPython/3.6.12
|
Release files / aws_stash-0.0.9-py3-none-any.whl
| Download URL | aws_stash-0.0.9-py3-none-any.whl |
|---|---|
| Size | 7.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f0e335d17ec5546e8c2c424b9da1ac2039fbaf86ab38f002423c1baa726a705a
|
|
BLAKE2b-256 checksum How to use checksums |
cc9bcb251af215c5cdfcb220adcd180be036007f4bf898da6339d7f8a603b4bd
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.6.0 requests/2.24.0 setuptools/40.6.2 requests-toolbelt/0.9.1 tqdm/4.50.2 CPython/3.6.12
|