{"id":16234477,"url":"https://github.com/aripalo/vegas-credentials","last_synced_at":"2025-09-11T23:40:11.521Z","repository":{"id":40364168,"uuid":"415294400","full_name":"aripalo/vegas-credentials","owner":"aripalo","description":"AWS credential_process utility to assume AWS IAM Roles with Yubikey Touch and Authenticator App TOTP MFA to provide temporary session credentials; With encrypted caching and support for automatic credential refresh.","archived":false,"fork":false,"pushed_at":"2024-04-30T08:18:51.000Z","size":5011,"stargazers_count":22,"open_issues_count":14,"forks_count":3,"subscribers_count":3,"default_branch":"main","last_synced_at":"2024-10-11T13:15:49.271Z","etag":null,"topics":["amazon-web-services","aws","credential-helper","credential-process","credential-provider","iam","mfa","multifactor-authentication","security","ykman","yubikey"],"latest_commit_sha":null,"homepage":"https://credentials.vegas/","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aripalo.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-10-09T11:50:08.000Z","updated_at":"2024-02-28T07:31:28.000Z","dependencies_parsed_at":"2024-06-19T05:28:10.714Z","dependency_job_id":"ad3ca246-2ea4-4a97-9a8f-e90495276ab5","html_url":"https://github.com/aripalo/vegas-credentials","commit_stats":null,"previous_names":["aripalo/aws-mfa-credential-process"],"tags_count":59,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aripalo%2Fvegas-credentials","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aripalo%2Fvegas-credentials/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aripalo%2Fvegas-credentials/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aripalo%2Fvegas-credentials/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aripalo","download_url":"https://codeload.github.com/aripalo/vegas-credentials/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":221663644,"owners_count":16859874,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["amazon-web-services","aws","credential-helper","credential-process","credential-provider","iam","mfa","multifactor-authentication","security","ykman","yubikey"],"created_at":"2024-10-10T13:16:09.626Z","updated_at":"2024-10-27T10:34:25.459Z","avatar_url":"https://github.com/aripalo.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"| **🚧 Work-in-Progress** | 🚀 ⁉️ Publish Plan |\n| :--------------------- | :--- |\n| Since version `v0.13.x` this tool is considered _\"mostly stable\"_: Breaking changes may occur if really needed but not arbitrarily. | I'm hoping to release `v1.0.0` during H2/2022. No commitments though! |\n---\n\n# ![Vegas Credentials](/assets/vegas-credentials.svg \"Vegas Credentials - AWS credential_process utility with optional Yubikey MFA support and smooth user experience to fetch, cache and refresh assumed temporary session credentials\")\n\n\u003e _Much like spending a week in Las Vegas at AWS re:Invent,_ using multiple AWS tools (SDKs, CLI, CDK, Terraform, etc) via command-line to assume IAM roles in different accounts with Multi-Factor Authentication can be an exhausting experience: `vegas-credentials` aims to simplify the credential process! _And just like you shouldn't stay too long in Las Vegas at once,_ this tool only deals with temporary sesssion credentials.\n\n\nVegas Credentials is an utility with smooth user experience that plugs into AWS [`credential_process`](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sourcing-external.html) to assume IAM Roles with [TOTP MFA](https://en.wikipedia.org/wiki/Time-based_One-Time_Password) (with optional [Yubikey Touch](https://www.yubico.com/products/yubikey-5-overview/) support) to fetch, cache and refresh assumed temporary session credentials.\n\n\u003cbr/\u003e\n\n\u003c!-- Badges --\u003e\n[![build](https://github.com/aripalo/vegas-credentials/actions/workflows/pipeline.yml/badge.svg)](https://github.com/aripalo/vegas-credentials/actions/workflows/pipeline.yml)\n[![Coverage](https://sonarcloud.io/api/project_badges/measure?project=aripalo_vegas-credentials\u0026metric=coverage\u0026token=983ccf9b47d7abae7857a352aa71fd52f953cd5c)](https://sonarcloud.io/summary/new_code?id=aripalo_vegas-credentials)\n[![Maintainability Rating](https://sonarcloud.io/api/project_badges/measure?project=aripalo_vegas-credentials\u0026metric=sqale_rating\u0026token=983ccf9b47d7abae7857a352aa71fd52f953cd5c)](https://sonarcloud.io/summary/new_code?id=aripalo_vegas-credentials)\n[![Security Rating](https://sonarcloud.io/api/project_badges/measure?project=aripalo_vegas-credentials\u0026metric=security_rating\u0026token=983ccf9b47d7abae7857a352aa71fd52f953cd5c)](https://sonarcloud.io/summary/new_code?id=aripalo_vegas-credentials)\n[![Vulnerabilities](https://sonarcloud.io/api/project_badges/measure?project=aripalo_vegas-credentials\u0026metric=vulnerabilities\u0026token=983ccf9b47d7abae7857a352aa71fd52f953cd5c)](https://sonarcloud.io/summary/new_code?id=aripalo_vegas-credentials)\n\u003c!-- /Badges --\u003e\n\n---\n\n\u003cbr/\u003e\n\n## Docs\n\n**For guides, examples and full documentation, go to https://credentials.vegas.**\n\n\n\n\u003cbr/\u003e\n\n## Install\n\n**Via [Homebrew](https://docs.brew.sh/Installation)** on MacOS, GNU/Linux and Windows Subsystem for Linux (WSL):\n\n```sh\nbrew install aripalo/tap/vegas-credentials\n```\n\n**Via [Scoop](https://scoop.sh/)** on Windows:\n\n```sh\nscoop bucket add aripalo https://github.com/aripalo/scoops.git \u0026\u0026 scoop install vegas-credentials\n```\n\n\n## Configure\n\n1. Configure your source profile and its credentials, most often it's the `default` one which you configure into `~/.aws/credentials`:\n\n    ```ini\n    # ~/.aws/credentials\n    [default]\n    aws_access_key_id = AKIAIOSFODNN7EXAMPLE\n    aws_secret_access_key = wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY\n    ```\n\n2. Configure your source profile in config:\n\n    ```ini\n    # ~/.aws/config\n    [default]\n    mfa_serial = arn:aws:iam::111111111111:mfa/FrankSinatra\n    ```\n\n    Note: if your source profile is not `default`, remember to add `profile` as prefix (`profile foo`)\n\n3. Configure your target profile with `credential_process` into `~/.aws/config`:\n\n    ```ini\n    # ~/.aws/config\n    [profile frank@concerts]\n    credential_process = vegas-credentials assume --profile=frank@concerts\n    vegas_role_arn=arn:aws:iam::222222222222:role/SingerRole\n    vegas_source_profile=default\n\n    # You may also provide any other additional standard AWS configuration, such as:\n    region = us-west-1\n    duration_seconds = 4383\n    role_session_name = SinatraAtTheSands\n    external_id = 0093624694724\n    ```\n\n    Note: `role_arn` \u0026 `source_profile` must be prefixed with `vegas_` to prevent AWS tooling to ignore `credential_process` setting and to prevent Terraform failing.\n\n4. Use any AWS tooling that support ini-based configuration with `credential_process`, like AWS CLI v2:\n    ```shell\n    aws sts get-caller-identity --profile frank@concerts\n    ```\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faripalo%2Fvegas-credentials","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Faripalo%2Fvegas-credentials","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Faripalo%2Fvegas-credentials/lists"}