3 ms·
Maybe that's because AWS' own aws-cli setup encourages you to store these credentials on disk in plaintext in a standard-named file in your home directory, and
by jffry 4y ago
Maybe that's because AWS' own aws-cli setup encourages you to store these credentials on disk in plaintext in a standard-named file in your home directory, and their best story for temporary roles is to invoke `aws sts get-session-token` and copy paste values from the JSON output to env vars.
It's really disappointed that aws-cli doesn't easily support this type of workflow, when using MFA and setting up multiple AWS accounts with cross-account roles are two things recommended as security best practices by AWS themselves.
Don't get me started on how you can only have a single U2F key attached to your root user.
- technion 4y agoI agree with that being a major part of the problem. Regarding root, I always create an account with a console login that can remove the root user mfa or reset a password, it becomes the recovery account and I can put its own key on it, and ideally never gets used once tested.
- layble 4y agoFought with getting a nice workflow with the cli that supports MFA. I got it working and wrote it up here. https://www.nicks.io/simplifying-using-the-aws-cli-with-mfa/ https://www.nicks.io/simplifying-using-the-aws-cli-with-mfa/