Skip to main content

awslogin

Python script for CLI and SDK access to AWS via ADFS while requiring MFA access using https://duo.com/

History and Purpose

BYU used to use the great aws-adfs CLI tool to login to our AWS accounts. It worked great, especially the DUO 2FA support. Eventually, we decided to write our own similar tool but make it BYU-specific so that we could tailor it to our needs (which basically means hard-code certain BYU-specific things) and remove some of the required parameters. Since this tool will be used by BYU employees only we had that option. We then morphed it a little more for our use cases. This isn’t something that you could use outside of BYU, sorry.

Installation

Upgrading

If you already have byu_awslogin install and are looking to upgrade simply run

pip3 install --upgrade byu_awslogin or pip install --upgrade byu_awslogin as appropriate for your python installation

Usage

awslogin defaults to the default profile in your ~/.aws/config and ~/.aws/credentials files. *If you already have a default profile you want to save in your ~/.aws files make sure to do that before running awslogin.*

Once you’re logged in, you can execute commands using the AWS CLI or AWS SDK. Try running aws s3 ls.

Currently, AWS temporary credentials are only valid for 1 hour. We cache your ADFS session, however, so you can just re-run awslogin again to get a new set of AWS credentials without logging in again to ADFS. Your ADFS login session is valid for 8 hours, after which time you’ll be required to login to ADFS again to obtain a new session.

To switch accounts after you’ve already authenticated to an account, just run awslogin again and select a new account/role combination.

To use it:

  • Run awslogin and it will prompt you for the AWS account and role to use.

  • Run awslogin --account <account name> --role <role name> to skip the prompting for account and name. You could specify just one of the arguments as well.

  • Run awslogin --profile <profile name> to specifiy an alternative profile

  • Run awslogin --region <region name> to specify a different region. The default region is us-west-2.

  • Run awslogin --status for the current status of the default profile

  • Run awslogin --status --profile dev for the current status of the dev profile

  • Run awslogin --status --profile all for the current status of the all profiles

  • Run awslogin --logout to logout of a cached ADFS session

  • Run awslogin --version to display the running version of awslogin

  • Run awslogin --help for full help message

Reporting bugs or requesting features

  • Enter an issue on the github repo.

  • Or, even better if you can, fix the issue and make a pull request.

Deploying changes

  • Update the version.

  • Commit the change and push. Handel-codepipeline will run the automated tests and if they pass it will build and upload a new version to pypi.

TODO

  • Write tests
    • Write more tests to increase overall coverage

Release files for byu-awslogin 0.13.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for byu-awslogin 0.13.0
File Size Uploaded
byu_awslogin-0.13.0.tar.gz 16.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for byu-awslogin 0.13.0
File Interpreter ABI Platform
byu_awslogin-0.13.0-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 39.4 kB

Release files / byu_awslogin-0.13.0.tar.gz

Download URL byu_awslogin-0.13.0.tar.gz
Size 16.4 kB
Tags Source
SHA-256 checksum
How to use checksums
9d5bba37bbee17e175e40f59bee008b5382642e1065f6d5e1a2898961f1868f5
BLAKE2b-256 checksum
How to use checksums
7002342a00805937d2d4f43911e5e29bd6241ab9fb5b20af80f5000e7536b4b3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release files / byu_awslogin-0.13.0-py2.py3-none-any.whl

Download URL byu_awslogin-0.13.0-py2.py3-none-any.whl
Size 23.0 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
2022c56f806405a31afa01ee4f2da26901bb42ed2f05230661304d2d3c7fe53e
BLAKE2b-256 checksum
How to use checksums
4d8fce5de431ad9c3e1ce0b892d3be4e039aaeee44b7dfc0aa6388cba0c098c2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

0.15.1

2 release files

0.14.2

2 release files

0.14.1

2 release files

0.14.0

2 release files

0.13.7

2 release files

0.13.6

2 release files

0.13.3

2 release files

0.13.2

2 release files

This release

0.13.0 This release

2 release files

0.12.8

2 release files

0.12.7

2 release files

0.12.6

2 release files

0.12.5

2 release files

0.12.4

2 release files

0.12.1

2 release files

0.12.0

2 release files

0.11.3

2 release files

0.11.1

2 release files

0.11.0

2 release files

0.10.8

2 release files

0.10.7

2 release files

0.10.6

2 release files

0.10.5

2 release files

0.10.4

2 release files

0.10.3

2 release files

0.10.2

2 release files

0.10.1

2 release files

0.9.17

2 release files

0.9.16

2 release files

0.9.15

2 release files

0.9.13

2 release files

0.9.12

2 release files

0.9.11

2 release files

0.9.10

2 release files

0.9.9

2 release files

0.9.8

2 release files

0.9.7

2 release files

0.9.6

2 release files

0.9.4

2 release files

0.9.3

2 release files

0.9.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page