generated from amazon-archives/__template_Apache-2.0
-
Notifications
You must be signed in to change notification settings - Fork 62
Open
Description
What I'm doing wrong here?
If I execute aws_signing_helper via command line, it returns, looks like, correct data
❯ aws_signing_helper credential-process \
--certificate ~/.ssh/client.crt \
--private-key ~/.ssh/client.key \
--trust-anchor-arn arn:aws:rolesanywhere:eu-west-1:******:trust-anchor/b****96 \
--profile-arn arn:aws:rolesanywhere:eu-west-1:****:profile/86*****e0 \
--role-arn arn:aws:iam::*****:role/test-Roles-Anywhere
{"Version":1,"AccessKeyId":"ASIA********","SecretAccessKey":"clW*******Bz","SessionToken":"IQoJ********Xk","Expiration":"2025-12-11T16:34:25Z"}
But when I have the same in ~/.aws/config like this
[profile rolesanywhere]
credential_process = aws_signing_helper credential-process \
--certificate ~/.ssh/client.crt \
--private-key ~/.ssh/client.key \
--trust-anchor-arn arn:aws:rolesanywhere:eu-west-1:*****:trust-anchor/bc********96 \
--profile-arn arn:aws:rolesanywhere:eu-west-1:*******:profile/86********e0 \
--role-arn arn:aws:iam::*******:role/test-Roles-Anywhere
and execute
aws ec2 describe-instances --instance-ids i-********* --query 'Reservations[0].Instances[0].[PrivateIpAddress]' --output text --profile rolesanywhere
it gives me
Error when retrieving credentials from custom-process: 2025/12/11 16:40:50 multiple matching identities
Metadata
Metadata
Assignees
Labels
No labels