Skip to main content

An aws-adfs spinoff that fits BYU's needs

Project description

awslogin
========

Python script for CLI and SDK access to AWS via ADFS while requiring MFA
access using https://duo.com/

History and Purpose
-------------------

BYU used to use the great
`aws-adfs <https://github.com/venth/aws-adfs>`__ CLI tool to login to
our AWS accounts. It worked great, especially the DUO 2FA support.
Eventually, we decided to write our own similar tool but make it
BYU-specific so that we could taylor it to our needs (which basically
means hard-code certain BYU-specific things) and remove some of the
required parameters. Since this tool will be used by BYU employees only
we had that option. We then morphed it a little more for our use cases.
This isn't something that you could use outside of BYU, sorry.

Installation
------------

- Install Python 3.x using your preferred method.
- See https://www.python.org/downloads/ for a windows installation
method.
- In linux you may be able to use apt, rpm or
https://www.python.org/downloads/.
- In Mac you can use homebrew, macports or
https://www.python.org/downloads/.
- Run ``pip3 install byu-awslogin``

Usage
-----

awslogin defaults to the default profile in your ~/.aws/config and
~/.aws/credentials files. ***If you already have a default profile you
want to save in your ~/.aws files make sure to do that before running
awslogin.***

| Once you're logged in, you can execute commands using the AWS CLI or
AWS SDK. Try running ``aws s3 ls``.
| Currently, awslogin tokens are only valid for 1 hour due to the
assume\_role\_with\_saml AWS API call has a max timeout of 1 hour.

To use it:

- Run ``awslogin`` and it will prompt you for the AWS account and role
to use.
- Run ``awslogin --account <account name> --role <role name>`` to skip
the prompting for account and name. You could specify just one of the
arguments as well.
- Run ``awslogin --profile <profile name>`` to specifiy an alternative
profile
- Run ``awslogin -- --help`` for full help message

Reporting bugs or requesting features
-------------------------------------

- Enter an issue on the github repo.
- Or, even better if you can, fix the issue and make a pull request.

Deploying changes
-----------------

- Update the version in the VERSION file.
- Commit the change and push. Handel-codepipeline will run the
automated tests and if they pass it will build and upload a new
version to pypi.

TODO
----

- gracefully handle the error case when the duo push is rejected
- Add support for profiles
- Authenticate once for 8 hours and rerun ``awslogin`` to relogin
- Write tests
- roles.py
- assume\_role.py



Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

byu_awslogin-0.9.15.tar.gz (9.6 kB view details)

Uploaded Source

Built Distribution

byu_awslogin-0.9.15-py3-none-any.whl (14.8 kB view details)

Uploaded Python 3

File details

Details for the file byu_awslogin-0.9.15.tar.gz.

File metadata

  • Download URL: byu_awslogin-0.9.15.tar.gz
  • Upload date:
  • Size: 9.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No

File hashes

Hashes for byu_awslogin-0.9.15.tar.gz
Algorithm Hash digest
SHA256 2c66868bf10e89344b0252f897e441a25c85aec5a16e04b58191386aa3059834
MD5 4c714e30342ab239080420f9a31c229d
BLAKE2b-256 2f883d113cbe74191d643edd7e98abb8f312841d7e0e44c1c99bab3c02f594bd

See more details on using hashes here.

File details

Details for the file byu_awslogin-0.9.15-py3-none-any.whl.

File metadata

File hashes

Hashes for byu_awslogin-0.9.15-py3-none-any.whl
Algorithm Hash digest
SHA256 c2a8d796815262d4f99d6c521be7a02263cfd99e2d5aedb4246cb7052bcc4dbf
MD5 6f9c5ce8340ec69a0ce64033af976716
BLAKE2b-256 1fbb80a1783e6f215467cdce4e11e6475125662b9c188db7105392012615fc14

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page