Skip to content

Run a command against a different permission set - #2

Merged
winebarrel merged 1 commit into
mainfrom
implement-sr
Sep 1, 2026
Merged

winebarrel merged 1 commit into
mainfrom
implement-sr

Conversation

@winebarrel

Copy link
Copy Markdown
Owner

A profile in ~/.aws/config pins exactly one sso_role_name, so reaching a second permission set in the same account has meant editing that file and remembering to put it back. The edit is global and outlives the command it was made for.

sr leaves the file alone. The profile still supplies the account, the start URL and the region; only the permission set is substituted, and only for the one child process the credentials are handed to.

sr -p example -r ReadOnlyAccess terraform plan

How

The substitution is config.WithSSOProviderOptions, applied after ssocreds.New has taken sso_role_name from the profile, so it wins. That leaves the profile resolution, the token cache and the refresh an [sso-session] profile is capable of to the SDK.

GetRoleCredentials is the only call made. What the account has is never listed — that would cost a call in front of the one that matters and would only move the same failure earlier — and there is no attempt to sign anyone in: a missing or expired token is reported with the aws sso login that fixes it.

A profile that gets its credentials some other way is refused rather than run, since the override would have been quietly ignored and the command would have used whatever that profile does use.

SR_ALIAS gives short names for permission sets. The expansion is local, so there is no lookup to wait for and no partial matching to be surprised by.

Notes

  • The command replaces sr rather than being spawned by it, so the terminal, the signals and the exit status all belong to it, and no parent is left holding the credentials. That makes sr Unix-only, and the release builds are limited to darwin and linux.
  • AWS_PROFILE is removed from the child's environment: left in place it would point back at the permission set being replaced.
  • Tests are black-box (package sr_test) and drive Cmd.Run against a stub Identity Center. Every function except ExecProcess, which does not return, is fully covered.

A profile in ~/.aws/config pins exactly one sso_role_name, so reaching a
second permission set in the same account has meant editing that file and
remembering to put it back. The edit is global and outlives the command it
was made for.

sr leaves the file alone. The profile still supplies the account, the start
URL and the region; only the permission set is substituted, and only for the
one child process the credentials are handed to.

    sr -p example -r ReadOnlyAccess terraform plan

The substitution is config.WithSSOProviderOptions, which is applied after
ssocreds.New has taken sso_role_name from the profile. That leaves the token
cache, and the refresh an [sso-session] profile is capable of, to the SDK.

GetRoleCredentials is the only call made: what the account has is never
listed, and there is no attempt to sign anyone in.
@winebarrel
winebarrel merged commit fd45251 into main Sep 1, 2026
2 checks passed
@winebarrel
winebarrel deleted the implement-sr branch September 1, 2026 03:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant