Assume an AWS IAM role and execute a command with the assumed credentials. AWS API credentials to assume the role must be set as environment variables, and the command and arguments are executed in the same manner as envdir.
envassume takes the effort out of assuming an AWS role from the command-line and copying/pasting the returned credentials to run a command. If you often need to do this:-
$ aws sts assume-role --role-arn arn:aws:iam::123456789012:role/s3_access --role-session-name s3_access_session
{
"AssumedRoleUser": {
"AssumedRoleId": "xxxxxxxxxxxxxxxxxxxxx:s3_access_session",
"Arn": "arn:aws:sts::123456789012:assumed-role/s3_access/s3_access_session"
},
"Credentials": {
"SecretAccessKey": "mmm",
"SessionToken": "nnn",
"Expiration": "2019-02-26T00:00:00Z",
"AccessKeyId": "ooo"
}
}
$ AWS_ACCESS_KEY_ID='ooo' AWS_SECRET_ACCESS_KEY='mmm' AWS_SESSION_TOKEN='nnn' aws s3 ls
It can be shortened to:-
$ envassume arn:aws:iam::123456789012:role/s3_access aws s3 ls
Useful if you often need to test roles, or run scripts with assumed roles on AWS instances using credentials from the instance profile.
Install
pip install envassume
Usage
usage: envassume [-h] [-i EXTERNAL_ID] [ARN] command [argument [argument ...]]
optional arguments:
-h, --help show this help message and exit
-i, --id EXTERNAL_ID external id
ARN AWS role ARN to assume (required if not set by environment variable)
environment variables:
environment must contain valid AWS API credentials
AWS_ASSUME_ROLE=ARN
no options can be present before the command if this is defined
AWS_ASSUME_ID=EXTERNAL_ID
License
Copyright (c) 2017 Warren Moore
This software may be redistributed under the terms of the MIT License. See the file LICENSE for details.
Contact
@wamonite - twitter
\_______.com - web
warren____________/ - email
Metadata
Release files for envassume 1.0.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| envassume-1.0.7.tar.gz | 4.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| envassume-1.0.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 11.2 kB
Release files / envassume-1.0.7.tar.gz
| Download URL | envassume-1.0.7.tar.gz |
|---|---|
| Size | 4.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
97f5f3f475759c159388c715354c4fc94ef13878698b8fca7a2f53ff98c9562f
|
|
BLAKE2b-256 checksum How to use checksums |
6e0f8ce47b2b34a73b4d8590f7fbf5cf12d1f9f36b0471d4f6563038423185ca
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.23.0 setuptools/46.1.1 requests-toolbelt/0.9.1 tqdm/4.45.0 CPython/3.8.2
|
Release files / envassume-1.0.7-py3-none-any.whl
| Download URL | envassume-1.0.7-py3-none-any.whl |
|---|---|
| Size | 6.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
149babb09b2aaaed4c92b7c363645a22051448850d9468c96d3fb02661e0cfdd
|
|
BLAKE2b-256 checksum How to use checksums |
ffe823156f34a3db79d929014da30898d9cdbeec36c882b36d5119fc9b79f424
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.1.1 pkginfo/1.5.0.1 requests/2.23.0 setuptools/46.1.1 requests-toolbelt/0.9.1 tqdm/4.45.0 CPython/3.8.2
|