3 ms·
Except if it is awscli creds, then of course there is no MFA.
by uniformlyrandom 6y ago
Except if it is awscli creds, then of course there is no MFA.
- LgWoodenBadger 6y agoWhat do you mean? Awscli supports key tokens from your 2fa device if your access keys are configured to require it
- LilBytes 6y agoThis has been a concern for me for a while, but it's possible to use aws cli with mfa by throwing an IdP in front of it. The work flow we used was AWS Vault -> Okta -> short lived AWS creds.
- Quiark 6y agoExactly, no workflow for terraform or CLI if you have U2F (Yubikey) 2FA.
- Hnrobert42 6y agoI really want to like U2F, but it’s use cases seem so limited.
- darkr 6y agoIf you use federated auth, then you can do whatever you want; 10 UDF keys and a video of a special dance if you so desire
- BillinghamJ 6y agoThat's not true. You can use AWS SSO with the CLI/SDKs (therefore including stuff like Terraform) with webauthn. It briefly pops you out to a browser to authenticate and caches a short lived token locally
- nijave 6y agoThere's AssumeRoleWithSAML so you can use any IdP There's tools like aws-okta that can advantage of that to supply short lived credentials which require 2FA You could also write a service that requires whatever authentication you want and returns the results of STS AssumeRole
- StreamBright 6y agoThere are way to limit the scope of those. One set of credentials per environment for example. You can also limit the use of the these credentials by policy. https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_examples_aws_deny-ip.html https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_p...
- Nextgrid 6y agoAWS STS solves this problem.