A local AWS credential broker daemon exposed over a Unix socket.
Project description
What is elhaz?
elhaz is a local AWS credential broker daemon exposed over a Unix socket.
Instead of a locally hosted HTTP metadata emulation service (ECS), which requires multiple processes for each assumed RoleArn, elhaz runs a single process (which accepts multiple concurrent connections) and serves automatically refreshed temporary AWS credentials on demand.
It caches AWS sessions for however long the daemon is kept alive, which eliminates redundant session creations and STS calls.
Unix-socket IPC is lightweight and gives a tighter local boundary than HTTP, avoids exposing local credential endpoints over TCP, and allows temporary credentials to live in memory rather than at rest on disk.
elhaz makes multi-role local AWS workflows cleaner by combining brokered access, in-memory caching, and host-local IPC in one model.
Installation
With uv:
uv tool install elhaz
With pipx:
pipx install elhaz
Usage
Refer to the quickstart guide.
License
elhaz is licensed by the Mozilla Public License 2.0 (MPL-2.0).
Contributing
Refer to the contributing guidelines.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file elhaz-0.1.4.tar.gz.
File metadata
- Download URL: elhaz-0.1.4.tar.gz
- Upload date:
- Size: 123.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bbc5c78ba7d19e02c8f23a52fff2104776fc7ff9c2958905ec82c3d031c4422c
|
|
| MD5 |
0999c2b77f6c0da09c2f73c68f83669a
|
|
| BLAKE2b-256 |
9ab40778cb61fe7501523d4bfa35c4cf1a7fbada88e23753ed049d62131d4eb2
|
Provenance
The following attestation bundles were made for elhaz-0.1.4.tar.gz:
Publisher:
push.yml on 61418/elhaz
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
elhaz-0.1.4.tar.gz -
Subject digest:
bbc5c78ba7d19e02c8f23a52fff2104776fc7ff9c2958905ec82c3d031c4422c - Sigstore transparency entry: 1155262659
- Sigstore integration time:
-
Permalink:
61418/elhaz@6fbc4ee590899eba48e08103aa9e4bdcc7afbfbe -
Branch / Tag:
refs/heads/main - Owner: https://github.com/61418
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
push.yml@6fbc4ee590899eba48e08103aa9e4bdcc7afbfbe -
Trigger Event:
push
-
Statement type:
File details
Details for the file elhaz-0.1.4-py3-none-any.whl.
File metadata
- Download URL: elhaz-0.1.4-py3-none-any.whl
- Upload date:
- Size: 37.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.7
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cfdfa2fd5fb7f049224e7006bbef009ccb9d2059827e17ac47e232aa83edaf1a
|
|
| MD5 |
5653c6054c629a28ddf86369954d65d6
|
|
| BLAKE2b-256 |
708327f10c9f4e3a23dc257a5f9ca465d1af30fdb5b09755fb1a6858d9f4a971
|
Provenance
The following attestation bundles were made for elhaz-0.1.4-py3-none-any.whl:
Publisher:
push.yml on 61418/elhaz
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
elhaz-0.1.4-py3-none-any.whl -
Subject digest:
cfdfa2fd5fb7f049224e7006bbef009ccb9d2059827e17ac47e232aa83edaf1a - Sigstore transparency entry: 1155262661
- Sigstore integration time:
-
Permalink:
61418/elhaz@6fbc4ee590899eba48e08103aa9e4bdcc7afbfbe -
Branch / Tag:
refs/heads/main - Owner: https://github.com/61418
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
push.yml@6fbc4ee590899eba48e08103aa9e4bdcc7afbfbe -
Trigger Event:
push
-
Statement type: