Skip to main content

CLI authentication for AWS credential exchange

Project description

CK-Prism-CLI - Authentication for AWS Credentials

Authenticates users via CloudKeeper Prism and exchanges tokens for AWS credentials.

Operating System Support

  • macOS
  • Linux
  • WSL on Windows
  • Windows

Python Support

Python 3.6 and above

Prerequisites

Software Prerequisites

  • Python 3.6 or above
  • AWS CLI v2 (optional, for using credentials)

Installation

pip3 install ck-prism

Verify installation:

ck-prism help

If command not found, add Python packages folder to PATH:

  • Linux: /home/{username}/.local/bin
  • macOS: /Users/{username}/Library/Python/{Python Version}/bin

Configuration

Interactive Configuration

ck-prism configure

You'll be prompted for:

Manual Configuration

Edit ~/.ck-prism/config.json:

{
  "default": {
    "realm": "cloudkeeper",
    "client_id": "ckauth-cli",
    "region": "us-east-1",
    "output": "json",
    "role_arn": "arn:aws:iam::123456789012:role/CKAuth-Admin,arn:aws:iam::123456789012:saml-provider/CKAuthProvider",
    "account_id": "123456789012",
    "role_name": "CKAuth-Admin"
  }
}

Named Profiles

ck-prism configure --profile production

Usage

Default Profile

ck-prism login

Named Profile

ck-prism login --profile production

The tool will:

  1. Check for cached tokens
  2. Refresh expired tokens automatically
  3. Open browser for initial authentication (if needed)
  4. Exchange token for AWS credentials
  5. Write credentials to ~/.aws/credentials

Using AWS Credentials

After login, use AWS CLI normally:

aws s3 ls
aws ec2 describe-instances

Or with named profile:

aws s3 ls --profile production

Managing Profiles

List Profiles

ck-prism profiles list

Remove a Profile

Interactive picker (asks for confirmation):

ck-prism profiles remove

By name, skipping confirmation:

ck-prism profiles remove production -y

Removing a profile cleans up:

  • The profile entry in ~/.ck-prism/config.json
  • The cached tokens file in ~/.ck-prism/tokens/
  • The matching section in ~/.aws/credentials

Token Caching

Tokens are cached in ~/.ck-prism/tokens/ and automatically refreshed when needed.

Troubleshooting

  • Command not found: Ensure Python packages directory is in PATH
  • Authentication failed: Re-run ck-prism login
  • Expired credentials: Run ck-prism login again to refresh

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ck_prism-1.5.2.tar.gz (25.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ck_prism-1.5.2-py3-none-any.whl (27.7 kB view details)

Uploaded Python 3

File details

Details for the file ck_prism-1.5.2.tar.gz.

File metadata

  • Download URL: ck_prism-1.5.2.tar.gz
  • Upload date:
  • Size: 25.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for ck_prism-1.5.2.tar.gz
Algorithm Hash digest
SHA256 25e18209b5e23856de8ac23d26624f7b30f2bf399af8e3f0e6726346a7ad19b5
MD5 212f38cb43c4eeb14a55684d32d49bab
BLAKE2b-256 6f5eb6b930e1ca87121ed52e54e700c179d3396fbd0999e7836826f6b764ad40

See more details on using hashes here.

File details

Details for the file ck_prism-1.5.2-py3-none-any.whl.

File metadata

  • Download URL: ck_prism-1.5.2-py3-none-any.whl
  • Upload date:
  • Size: 27.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.13.3

File hashes

Hashes for ck_prism-1.5.2-py3-none-any.whl
Algorithm Hash digest
SHA256 5d0a89dcff65dbf163c8c6adaa15b2640d03a8f1e696cd738587affbca0c14af
MD5 6026e57103d5bf385526c673ade42b15
BLAKE2b-256 aa0de5bb8d7b8995ecc7accec65a1ad675ff4a0a2771e224f4195546503097bf

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page