Docker image for AWS CLI in FH DaSL's WILDS
10K+
This directory contains Docker images for AWS CLI, the unified command-line interface for Amazon Web Services.
latest ( Dockerfile | Vulnerability Report )2.27.49 ( Dockerfile | Vulnerability Report )These Docker images are built from Ubuntu Noble (24.04 LTS) base image and include:
The images are designed to be minimal and focused on providing AWS CLI functionality for accessing public cloud datasets, with additional samtools support for BAM file processing. The inclusion of AWS Signing Helper enables certificate-based authentication for more secure access to private AWS resources when needed.
Platform Support: This image supports both linux/amd64 and linux/arm64 (Apple Silicon). The Dockerfile uses Docker's TARGETARCH build argument to automatically download the correct architecture-specific binaries during the build process.
Note: AWS Signing Helper is only available on linux/amd64. ARM64 images include AWS CLI and samtools but not the signing helper. This means certificate-based authentication (IAM Roles Anywhere) is only available on AMD64 platforms. Traditional IAM credentials and public data access (--no-sign-request) work on both architectures.
docker pull getwilds/awscli:latest
# or
docker pull getwilds/awscli:2.27.49
# Alternatively, pull from GitHub Container Registry
docker pull ghcr.io/getwilds/awscli:latest
apptainer pull docker://getwilds/awscli:latest
# or
apptainer pull docker://getwilds/awscli:2.27.49
# Alternatively, pull from GitHub Container Registry
apptainer pull docker://ghcr.io/getwilds/awscli:latest
This image now supports multiple authentication methods:
Recommended for most bioinformatics workflows
# Download public data (no AWS credentials required)
docker run --rm -v /path/to/data:/data getwilds/awscli:latest \
aws s3 sync --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/ /data/
For secure access to private AWS resources using x.509 certificates:
# Mount certificates and configure AWS CLI to use signing helper
docker run --rm \
-v /path/to/certs:/certs:ro \
-v /path/to/data:/data \
-e AWS_PROFILE=roles-anywhere \
getwilds/awscli:latest \
aws s3 ls s3://private-bucket/
Example AWS CLI configuration for certificate authentication:
# ~/.aws/config
[profile roles-anywhere]
credential_process = aws_signing_helper credential-process \
--certificate /certs/client.crt \
--private-key /certs/client.key \
--trust-anchor-arn arn:aws:rolesanywhere:region:account:trust-anchor/ta-id \
--profile-arn arn:aws:rolesanywhere:region:account:profile/profile-id \
--role-arn arn:aws:iam::account:role/role-name
If you must use traditional AWS credentials, mount them carefully:
# Use with caution - not recommended for production
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v /path/to/data:/data \
getwilds/awscli:latest \
aws s3 ls s3://private-bucket/
Recommended: Public Data Access (No Credentials Required)
# Download public data (no AWS credentials required)
docker run --rm -v /path/to/data:/data getwilds/awscli:latest \
aws s3 sync --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/ /data/
# List contents of a public S3 bucket
docker run --rm getwilds/awscli:latest \
aws s3 ls --no-sign-request s3://gatk-test-data/
# Copy specific files from public bucket
docker run --rm -v /path/to/data:/data getwilds/awscli:latest \
aws s3 cp --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/NA12878.bam /data/
# Using Apptainer for public data
apptainer run --bind /path/to/data:/data docker://getwilds/awscli:latest \
aws s3 sync --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/ /data/
Download GATK Test Data:
# Get small test BAM files (< 1GB)
docker run --rm -v $(pwd):/data getwilds/awscli:latest \
aws s3 sync --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/ /data/test-bams/
Download and Filter BAM Files:
# Download test BAM and subset to chromosome 1 only
docker run --rm -v $(pwd):/data getwilds/awscli:latest bash -c "
aws s3 cp --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/NA12878.bam /data/ &&
samtools view -b /data/NA12878.bam chr1 > /data/NA12878_chr1.bam &&
samtools index /data/NA12878_chr1.bam
"
# Create an even smaller test file with first 1000 reads
docker run --rm -v $(pwd):/data getwilds/awscli:latest bash -c "
aws s3 cp --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/NA12878.bam /data/ &&
samtools view -b /data/NA12878.bam | head -n 1000 | samtools view -b > /data/NA12878_1k.bam
"
Download Reference Genomes:
# Download reference files from public buckets
docker run --rm -v $(pwd):/data getwilds/awscli:latest \
aws s3 cp --no-sign-request s3://broad-references/hg38/v0/Homo_sapiens_assembly38.fasta /data/
Batch Download ENCODE Data:
# Download multiple files with filtering
docker run --rm -v $(pwd):/data getwilds/awscli:latest \
aws s3 sync --no-sign-request s3://encode-public/2020/01/01/ /data/ --exclude "*" --include "*.bam"
BAM File Quality Control:
# Download and check BAM file statistics
docker run --rm -v $(pwd):/data getwilds/awscli:latest bash -c "
aws s3 cp --no-sign-request s3://gatk-test-data/wgs_bam/NA12878_20k_b37/NA12878.bam /data/ &&
samtools flagstat /data/NA12878.bam > /data/NA12878_stats.txt &&
samtools idxstats /data/NA12878.bam > /data/NA12878_idxstats.txt
"
The AWS CLI Docker images include:
--no-install-recommends to minimize dependenciesRecommended: Public Data Only
--no-sign-request flag for public S3 bucketsAcceptable: Certificate-Based Authentication
Not Recommended: Traditional IAM Credentials
~/.aws) into containers when possibleThese images are regularly scanned for vulnerabilities using Docker Scout. However, due to the nature of bioinformatics software and their dependencies, some Docker images may contain components with known vulnerabilities (CVEs).
Use at your own risk: While we strive to minimize security issues, these images are primarily designed for research and analytical workflows in controlled environments.
For the latest security information about this image, please check the CVEs_*.md files in this directory, which are automatically updated through our GitHub Actions workflow. If a particular vulnerability is of concern, please file an issue in the GitHub repo citing which CVE you would like to be addressed.
For public datasets, no configuration is required. Simply use the --no-sign-request flag:
aws s3 [command] --no-sign-request s3://public-bucket/path/
Popular Public Bioinformatics Datasets:
s3://gatk-test-data/ - GATK test datasetss3://broad-references/ - Reference genomess3://encode-public/ - ENCODE consortium datas3://1000genomes/ - 1000 Genomes Project dataTo use AWS IAM Roles Anywhere with certificates:
# Create AWS config file
mkdir -p ~/.aws
cat > ~/.aws/config << EOF
[profile roles-anywhere]
credential_process = aws_signing_helper credential-process \\
--certificate /path/to/client.crt \\
--private-key /path/to/client.key \\
--trust-anchor-arn arn:aws:rolesanywhere:region:account:trust-anchor/ta-id \\
--profile-arn arn:aws:rolesanywhere:region:account:profile/profile-id \\
--role-arn arn:aws:iam::account:role/role-name
EOF
docker run --rm \
-v ~/.aws:/root/.aws:ro \
-v /path/to/certs:/certs:ro \
-e AWS_PROFILE=roles-anywhere \
getwilds/awscli:latest \
aws s3 ls
The Dockerfile follows these main steps:
pipefail)These Dockerfiles are maintained in the WILDS Docker Library repository.
Content type
Image
Digest
sha256:db9ee62ac…
Size
100.5 MB
Last updated
12 months ago
docker pull getwilds/awscli