Sign inSign up

wonderbitcom/keycloak_aws_generate_keys

By wonderbitcom

•Updated over 1 year ago

A way to retrieve keys for AWS from Keycloak

Image
Security
0

1.3K

wonderbitcom/keycloak_aws_generate_keys repository overview

⁠What is this?

This is a docker image built for ARM and AMD that allows a user to get AWS credentials from the Keycloak IDP. This only works if Keycloak has been configured previously as a SAML authentication mechanism for AWS.

The credentials are stored inside the container in ~/.aws/credentials.

⁠Updating from a previous version


⚠️ Warning!

If you are updating from a previous version (unfortunately the previous version was stupidly named latest), you will need to change the environment variables as follows:

  • SSO_USERNAME becomes IDP_USERNAME;
  • SSO_PASSWORD becomes IDP_PASSWORD.

Additionally, you will NOT need to run the CMD python3 /code/generate_aws_credentials_osenv.py as it will run the script by default. If you want to explicitly run the script you will need to use python3 /aws/main.py.


⁠To run

docker run --rm -ti \
-e AWS_REGION="us-east-1" \
-e IDP_ENTRY_URL="https://<your-domain.com>:443/realms/<your-realm>/protocol/saml/clients/<amazon-aws>" \
-e IDP_USERNAME="<your-idp-username>" \
-e IDP_PASSWORD="<your-idp-password>" \
-e AWS_CONFIG_HEAD="saml" \
-v $PWD/.aws:/.aws \
wonderbitcom/keycloak_aws_generate_keys:0.0.3

Your AWS credentials will be then available in $PWD/.aws/credentials under the [saml] category.

Tag summary

Content type

Image

Digest

sha256:f1e7563e5…

Size

319.7 MB

Last updated

almost 4 years ago

docker pull wonderbitcom/keycloak_aws_generate_keys