Skip to content

Prompt for MFA before assuming a role - #10

Merged
ashishjullia merged 1 commit into
mainfrom
mfa-before-role
Sep 25, 2026
Merged

ashishjullia merged 1 commit into
mainfrom
mfa-before-role

Conversation

@ashishjullia

Copy link
Copy Markdown
Owner

Summary

  • When a Portunus project sets AWS_ROLE_TO_ASSUME and AWS_MFA_SERIAL, startup asks for an MFA code before assuming that project's role.
  • The role ARN, MFA serial, region, and IAM user keys all come from that project. A different dev <project>/<stage> can omit any of them.
  • The one-time code is typed at the prompt and is not stored in Portunus.

Test plan

  • dev with no project still opens a shell and does not ask for MFA.
  • A project with keys and a role, and no AWS_MFA_SERIAL, assumes the role without a prompt.
  • A project with AWS_MFA_SERIAL prompts for a code, then the caller is the assumed role.
  • A wrong or empty code exits and does not open a shell as the IAM user.

…MFA_SERIAL.

The serial, role, and IAM user keys stay in Portunus for each project and stage. The one-time code is typed at startup.
@ashishjullia
ashishjullia merged commit ce996e5 into main Sep 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant