Skip to main content
Yanked

This release has been yanked by its maintainers, and will be ignored by installers, except when explicitly specified.
Consider using release 1.4.0 instead.

aws2-wrap

Quality Gate Status

This is a simple script to make it easier to use AWS Single Sign On credentials with tools that don't understand the sso entries in an AWS profile.

The script provides the following capabilities:

  • Run a command using AWS SSO credentials
  • Generate a temporary profile in the $AWS_CONFIG_FILE and $AWS_SHARED_CREDENTIALS_FILE file
  • Exporting the AWS SSO credentials
  • Use the credentials via .aws/config
  • Assume a role via AWS SSO

Please note that the script is called aws2-wrap to show that it works with AWS CLI v2, even though the CLI tool is no longer called aws2.

Install using pip

https://pypi.org/project/aws2-wrap

pip3 install aws2-wrap==1.2.4

Run a command using AWS SSO credentials

aws2-wrap [--profile <awsprofilename>] [--exec] <command>

Note that if you are using --exec and <command> contains spaces, it must be surrounded with double-quotation marks.

You can also specify the profile to be used via AWS_PROFILE which then allows the same profile to be used by subsequent tools and commands.

Examples:

aws2-wrap --profile MySSOProfile terraform plan

aws2-wrap --profile MySSOProfile --exec "terraform plan"

AWS_PROFILE=MySSOProfile aws2-wrap terraform plan

If you are having problems with the use of quotes in the command, you may find one of the other methods works better for you.

Generate a temporary profile in the $AWS_CONFIG_FILE and $AWS_SHARED_CREDENTIALS_FILE file

There are some utilities which work better with the configuration files rather than the environment variables. For example, if you need to access more than one profile at a time.

aws2-wrap --generate --profile $AWS_PROFILE --credentialsfile $AWS_SHARED_CREDENTIALS_FILE --configfile $AWS_CONFIG_FILE --outprofile $DESTINATION_PROFILE

Optionally, you can specify --generatestdout instead of --generate. --outprofile is still required in order to name the section but --credentialsfile and --configfile are ignored. With this command option, the generated credentials will then be output to the console.

Export the AWS SSO credentials

There may be circumstances when it is easier/better to set the appropriate environment variables so that they can be re-used by any aws command.

Since the script cannot directly set the environment variables in the calling shell process, it is necessary to use the following syntax:

eval "$(aws2-wrap [--profile <awsprofilename>] --export)"

For example:

eval "$(aws2-wrap --profile MySSOProfile --export)"

If you are using PowerShell, the equivalent command is:

aws2-wrap --profile MySSOProfile --export | invoke-expression

Use the credentials via .aws/config

If you are using a tool that works with normal AWS credentials but doesn't understand the new AWS SSO credentials, another option is to add a profile to .aws/config that calls the aws2-wrap script.

For example, add the following block to .aws/config:

[profile Wrapped]
credential_process = aws2-wrap --process --profile <awsprofilename>

then, after authentication, you can run any command that uses AWS credentials by specifying the "Wrapped" profile:

aws sso login --profile <awsprofilename>
export AWS_PROFILE=Wrapped
export AWS_SDK_LOAD_CONFIG=1
terraform plan

Note that because the profile is being specified via AWS_PROFILE, it is sometimes necessary (as shown above) to set AWS_SDK_LOAD_CONFIG in order to get tools like terraform to successfully retrieve the credentials.

Assume a role via AWS SSO

Your .aws/config file can look like this:

[default]
sso_start_url = xxxxxxxxxxxx
sso_region = us-west-2
sso_account_id = xxxxxxxxxxxx
sso_role_name = SSORoleName

[profile account1]
role_arn = arn:aws:iam::xxxxxxxxxxxx:role/role-to-be-assumed
source_profile = default
region = ap-northeast-1

allowing you to then run:

aws2-wrap --profile account1 <command>

and <command> will be run under role-to-be-assumed.

Contributing

Contributions are more than welcome, particularly if you are able to expand on the test code. Please ensure, though, that before you submit a Pull Request, you run make test to ensure that your changes don't break any of the existing tests and make pylint to ensure that the linter is happy. Please note that the CI/CD pylint test may use different pylint rules from your own local setup.

Credits

Thanks to @l1n, @sodul, @damian-bisignano, @flyinprogrammer, @abeluck, @topu, @bigwheel, @krabbit, @jscook2345, @hieki, @blazdivjak, @fukushun1994, @johann8384, @ppezoldt, @atwoodjw, @lummish, @life36-vinny and @lukemassa for their contributions.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

aws2-wrap-1.2.5.tar.gz (9.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

aws2_wrap-1.2.5-py3-none-any.whl (21.2 kB view details)

Uploaded Python 3

File details

Details for the file aws2-wrap-1.2.5.tar.gz.

File metadata

  • Download URL: aws2-wrap-1.2.5.tar.gz
  • Upload date:
  • Size: 9.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.2.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.2.0 requests-toolbelt/0.9.1 tqdm/4.48.2 CPython/3.8.10

File hashes

Hashes for aws2-wrap-1.2.5.tar.gz
Algorithm Hash digest
SHA256 93a455c03e755e45b3b6eb0b926c427d0703d7f71229a50a9447d7bf987fef73
MD5 f5652b1535a90faec78a4fd884c2e2ea
BLAKE2b-256 827bf52b34b287094a52c3570cdd708b5fa4017a69be0abc88fdce5a1c023ed6

See more details on using hashes here.

File details

Details for the file aws2_wrap-1.2.5-py3-none-any.whl.

File metadata

  • Download URL: aws2_wrap-1.2.5-py3-none-any.whl
  • Upload date:
  • Size: 21.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.2.0 pkginfo/1.5.0.1 requests/2.22.0 setuptools/45.2.0 requests-toolbelt/0.9.1 tqdm/4.48.2 CPython/3.8.10

File hashes

Hashes for aws2_wrap-1.2.5-py3-none-any.whl
Algorithm Hash digest
SHA256 a36210865c03ac912a25b341b7c901360d82232e588a29b606ba17b7cf326414
MD5 8421df45dbb3ffde8d9a1a1f85242608
BLAKE2b-256 0ea184c3a954ef3a027e07ec47607a42d6a68a042b2fc7e9b238d7562d7e79e7

See more details on using hashes here.

Release history Release notifications | RSS feed

1.4.0

2 files

1.3.1

2 files

1.3.0

2 files

1.2.8

2 files

1.2.7

2 files

1.2.6

2 files

This release

1.2.5 This release

2 files

1.2.4

2 files

1.2.3

2 files

1.2.2

2 files

1.2.1

2 files

1.2.0

2 files

1.1.11

2 files

1.1.10

2 files

1.1.9

2 files

1.1.8

2 files

1.1.7

2 files

1.1.6

2 files

1.1.5

2 files

1.1.4

2 files

1.1.3

2 files

1.1.2

2 files

1.1.1

2 files

1.1.0

2 files

1.0.3

1 file

1.0.2

2 files

1.0.1

2 files

1.0.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page