logoalt Hacker News

shushpanchiklast Monday at 6:55 AM3 repliesview on HN

> // TODO: Handle credential_source, role_arn, source_profile, sso_*, etc.

So it does not support any meaningful multi-account login (SSO, org role assumption, etc), and requires AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY. That's a no-no from security POV for anything in production, so not sure what's the meaningful way to use that.


Replies

huseyinbaballast Monday at 7:50 AM

I also care security part, but this is just beginning :) New features will be added iteratively based on community requests, and it seems there are plenty of good requirements in HN thread, thanks

zeroimpllast Monday at 11:29 AM

You or the developer could piggy back on “aws configure export-credentials --profile profile-name —-format process” to support any authentication that the CLI supports.

fosronlast Monday at 7:46 AM

Yeah, without SSO support this is a no-go for me too.