Skip to main content

CLI authentication for AWS credential exchange

Project description

CK-Prism-CLI - Authentication for AWS Credentials

Authenticates users via CloudKeeper Prism and exchanges tokens for AWS credentials.

Operating System Support

  • macOS
  • Linux
  • WSL on Windows
  • Windows

Python Support

Python 3.6 and above

Prerequisites

Software Prerequisites

  • Python 3.6 or above
  • AWS CLI v2 (optional, for using credentials)

Installation

pip3 install ck-prism

Verify installation:

ck-prism help

If command not found, add Python packages folder to PATH:

  • Linux: /home/{username}/.local/bin
  • macOS: /Users/{username}/Library/Python/{Python Version}/bin

Configuration

Interactive Configuration

ck-prism configure

You'll be prompted for:

Manual Configuration

Edit ~/.ck-prism/config.json:

{
  "default": {
    "realm": "cloudkeeper",
    "client_id": "ckauth-cli",
    "region": "us-east-1",
    "output": "json",
    "role_arn": "arn:aws:iam::123456789012:role/CKAuth-Admin,arn:aws:iam::123456789012:saml-provider/CKAuthProvider",
    "account_id": "123456789012",
    "role_name": "CKAuth-Admin"
  }
}

Named Profiles

ck-prism configure --profile production

Usage

Default Profile

ck-prism login

Named Profile

ck-prism login --profile production

The tool will:

  1. Check for cached tokens
  2. Refresh expired tokens automatically
  3. Open browser for initial authentication (if needed)
  4. Exchange token for AWS credentials
  5. Write credentials to ~/.aws/credentials

Using AWS Credentials

After login, use AWS CLI normally:

aws s3 ls
aws ec2 describe-instances

Or with named profile:

aws s3 ls --profile production

Managing Profiles

List Profiles

ck-prism profiles list

Remove a Profile

Interactive picker (asks for confirmation):

ck-prism profiles remove

By name, skipping confirmation:

ck-prism profiles remove production -y

Removing a profile cleans up:

  • The profile entry in ~/.ck-prism/config.json
  • The cached tokens file in ~/.ck-prism/tokens/
  • The matching section in ~/.aws/credentials

Token Caching

Tokens are cached in ~/.ck-prism/tokens/ and automatically refreshed when needed.

Troubleshooting

  • Command not found: Ensure Python packages directory is in PATH
  • Authentication failed: Re-run ck-prism login
  • Expired credentials: Run ck-prism login again to refresh

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ck_prism-1.5.0.tar.gz (23.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ck_prism-1.5.0-py3-none-any.whl (25.8 kB view details)

Uploaded Python 3

File details

Details for the file ck_prism-1.5.0.tar.gz.

File metadata

  • Download URL: ck_prism-1.5.0.tar.gz
  • Upload date:
  • Size: 23.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for ck_prism-1.5.0.tar.gz
Algorithm Hash digest
SHA256 9c0df9900b1a2fa43ce99c4b27debffa37c2ee04db0f1e0fea4b732b06ad5935
MD5 880464fecd23056f6881bcadd401392d
BLAKE2b-256 fab1fbf9465a0077bafaae76f394e86855eaac54ccee6ed068f2ac9cee94d652

See more details on using hashes here.

File details

Details for the file ck_prism-1.5.0-py3-none-any.whl.

File metadata

  • Download URL: ck_prism-1.5.0-py3-none-any.whl
  • Upload date:
  • Size: 25.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for ck_prism-1.5.0-py3-none-any.whl
Algorithm Hash digest
SHA256 b13e041d92f9536c093fab8c55d8f744672269baaf35f4cf998e4e45e50bf000
MD5 dd3606ed0c571a95220737278f3801fb
BLAKE2b-256 9378784b2b28a7362d07d755fb410869429134a1a48974e23ce584319befba31

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page