Sign inSign up

perionnet/okta-awscli

By perionnet

•Updated about 4 years ago

okta-awscli

Image
0

2.2K

perionnet/okta-awscli repository overview

⁠okta-awscli

This Dockerfile is using https://github.com/oktadeveloper/okta-aws-cli-assume-role⁠ tool version 2.0.0

⁠Prerequiste:

  1. Install Docker⁠.
  2. create directory under: ~/.aws (Linux), %USERPROFILE%/.aws (Windows)
  3. Create a file under %userprofile%/.okta/config.properties with the following configuration:
⁠Minimum

#OktaAWSCLI OKTA_ORG=my.org.com OKTA_AWS_APP_URL= OKTA_BROWSER_AUTH=false OKTA_USERNAME=your_username OKTA_STS_DURATION=43200

⁠Only for windows check the 'shared' from the 'Docker for windows'

Image of Docker for windows

⁠Usage:

Windows: docker run -v %USERPROFILE%\.okta\config.properties:/root/.okta/config.properties -v %USERPROFILE%\.aws:/root/.aws/ -it perionnet/okta-awscli

Linux: docker run -v ~/.okta/config.properties:/root/.okta/config.properties -v ~/.aws/:/root/.aws/ -it perionnet/okta-awscli

⁠THe full configuration options:

  • OKTA_ORG which is the url of your Okta org (starting with https://).
  • OKTA_AWS_APP_URL is the url link of your Okta AWS application url (see below for more info)
  • OKTA_USERNAME is the username to use. If present will skip username input.
  • OKTA_PASSWORD_CMD is the command to fetch your password instead of showing a password prompt. Read more...⁠
  • OKTA_ENV_MODE set to true to run sub-command with AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, and AWS_SESSION_TOKEN env vars set. Temporary credentials are shared in memory and kept off disk in this mode. (default: false)
  • OKTA_BROWSER_AUTH Must be false when using with docker
  • OKTA_COOKIES_PATH is directory path to store cookies.properties for Okta. This is particularly useful when running this tool in many concurrent processes like you might with OKTA_ENV_MODE (default: ~/.okta)
  • OKTA_PROFILE is the name of the AWS profile to create/reuse. May also be specified on the commandline by --profile. (default: get AWS profile name based on per-session STS user name)
  • OKTA_AWS_REGION is the default AWS region to store with the created profile.
  • OKTA_AWS_ROLE_TO_ASSUME is the IAM Role ARN to use. If present will try to match okta account's retrieved role list and use it. Will still prompt if no match found. (ex: arn:aws:iam::123456789012:role/EC2-Admins)
  • OKTA_STS_DURATION is the duration the role will be assumed, in seconds. The maximum session duration allowed by AWS is 12 hours and this needs to be set on the role as well. Defaults to 1hr.
  • OKTA_MFA_CHOICE is the provider and factor type to use if prompted for MFA. Example: OKTA.push. See Factors documentation⁠ for values. (default: use single factor or prompt user to select from usable factors).

Tag summary

Content type

Image

Digest

sha256:9743b6ef1…

Size

339.8 MB

Last updated

about 4 years ago

docker pull perionnet/okta-awscli