CK-Prism-CLI - Authentication for AWS Credentials
Authenticates users via CloudKeeper Prism and exchanges tokens for AWS credentials.
Operating System Support
macOSLinuxWSL on WindowsWindows
Python Support
Python 3.6 and above
Prerequisites
Software Prerequisites
- Python 3.6 or above
- AWS CLI v2 (optional, for using credentials)
Installation
pip3 install ck-prism
Verify installation:
ck-prism help
If command not found, add Python packages folder to PATH:
- Linux:
/home/{username}/.local/bin - macOS:
/Users/{username}/Library/Python/{Python Version}/bin
Configuration
Interactive Configuration
ck-prism configure
You'll be prompted for:
- Prism Domain: This can be found in your Prism instance - "https://prism.cloudkeeper.com" , "https://myprism.xyz.in"
- Prism Tenant: This can be found in your Prism SSO Url - "https://sso.prism.cloudkeeper.com' here, 'sso' is your Prism tenant
- AWS Region: Default is
us-east-1
Manual Configuration
Edit ~/.ck-prism/config.json:
{
"default": {
"realm": "cloudkeeper",
"client_id": "ckauth-cli",
"region": "us-east-1",
"output": "json",
"role_arn": "arn:aws:iam::123456789012:role/CKAuth-Admin,arn:aws:iam::123456789012:saml-provider/CKAuthProvider",
"account_id": "123456789012",
"role_name": "CKAuth-Admin"
}
}
Named Profiles
ck-prism configure --profile production
Usage
Default Profile
ck-prism login
Named Profile
ck-prism login --profile production
The tool will:
- Check for cached tokens
- Refresh expired tokens automatically
- Open browser for initial authentication (if needed)
- Exchange token for AWS credentials
- Write credentials to
~/.aws/credentials
Using AWS Credentials
After login, use AWS CLI normally:
aws s3 ls
aws ec2 describe-instances
Or with named profile:
aws s3 ls --profile production
Managing Profiles
List Profiles
ck-prism profiles list
Remove a Profile
Interactive picker (asks for confirmation):
ck-prism profiles remove
By name, skipping confirmation:
ck-prism profiles remove production -y
Removing a profile cleans up:
- The profile entry in
~/.ck-prism/config.json - The cached tokens file in
~/.ck-prism/tokens/ - The matching section in
~/.aws/credentials
Token Caching
Tokens are cached in ~/.ck-prism/tokens/ and automatically refreshed when needed.
Troubleshooting
- Command not found: Ensure Python packages directory is in PATH
- Authentication failed: Re-run
ck-prism login - Expired credentials: Run
ck-prism loginagain to refresh
Metadata
Release files for ck-prism 1.5.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ck_prism-1.5.2.tar.gz | 25.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ck_prism-1.5.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 52.7 kB
Release files / ck_prism-1.5.2.tar.gz
| Download URL | ck_prism-1.5.2.tar.gz |
|---|---|
| Size | 25.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
25e18209b5e23856de8ac23d26624f7b30f2bf399af8e3f0e6726346a7ad19b5
|
|
BLAKE2b-256 checksum How to use checksums |
6f5eb6b930e1ca87121ed52e54e700c179d3396fbd0999e7836826f6b764ad40
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.3
|
Release files / ck_prism-1.5.2-py3-none-any.whl
| Download URL | ck_prism-1.5.2-py3-none-any.whl |
|---|---|
| Size | 27.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5d0a89dcff65dbf163c8c6adaa15b2640d03a8f1e696cd738587affbca0c14af
|
|
BLAKE2b-256 checksum How to use checksums |
aa0de5bb8d7b8995ecc7accec65a1ad675ff4a0a2771e224f4195546503097bf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.13.3
|