forked from DanteInc/aws-assume-role-cicd
-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathindex.js
executable file
·56 lines (49 loc) · 1.33 KB
/
index.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
#!/usr/bin/env node
const AWS = require("aws-sdk");
const argv = require("commander");
argv
.option(
"-r --role [arn]",
"Role ARN to assume (env AWS_ROLE default)",
process.env.AWS_ROLE
)
.option(
"-d --duration [seconds]",
"Session length (30 minute default)",
Number,
process.env.AWS_SESSION_DURATION || 1800
)
.option("-b --debug")
.parse(process.argv);
const assumeRole = (role, duration, debug) => {
AWS.config.logger = debug ? process.stdout : undefined;
const params = {
RoleArn: role,
RoleSessionName: "aws-assume-role",
DurationSeconds: duration,
};
const STS = new AWS.STS();
return STS.assumeRole(params)
.promise()
.then((data) => {
const { AccessKeyId, SecretAccessKey, SessionToken } = data.Credentials;
process.stdout.write(
`AWS_ACCESS_KEY_ID=${AccessKeyId} AWS_SECRET_ACCESS_KEY=${SecretAccessKey} AWS_SESSION_TOKEN=${SessionToken}`
);
});
};
const run = () => {
const { role, duration, debug } = argv;
if (debug) console.log("args: ", { role, duration, debug });
if (!role)
return Promise.reject(
new Error(
"No role is set via 'AWS_ROLE env var' or '--role option'. See --help."
)
);
return assumeRole(role, duration, debug);
};
run().catch((err) => {
console.error(err.message);
process.exit(1);
});