In earlier posts, I set up:
- AWS Organizations
- IAM Identity Center
- Permission Set
That's as far as I'd gotten.
This time, I'll connect the AWS CLI to IAM Identity Center (AWS SSO) so I can operate AWS from my local machine.
This means I can use the AWS CLI and Terraform securely, without ever issuing long-lived access keys.
Why avoid access keys?
Previously, when using the AWS CLI, I'd create an IAM user and issue
- Access Key ID
- Secret Access Key
credentials.
IAM User
├── Access Key ID
└── Secret Access Key
However, this approach comes with a number of problems.
- Risk of the access key leaking
- Needs periodic rotation
- Has to be stored in GitHub Secrets
- Becomes messy to manage when someone leaves
These days, AWS recommends using **IAM Identity Center (formerly AWS SSO)** for human access to AWS.
Reference
How IAM Identity Center and the AWS CLI work together
The AWS CLI logs in to IAM Identity Center and obtains temporary credentials.
Developer PC
│
aws configure sso
│
▼
IAM Identity Center
│
▼
AdministratorAccess
│
▼
Dev Account
In short:
- No password is stored
- No access key is stored
- Temporary credentials are fetched only when needed
— which adds up to a much more secure authentication approach.
Running aws configure sso
First, install AWS CLI v2.
Once it's installed, run the following command.
aws configure sso
This kicks off an interactive setup flow.
SSO Session Name
SSO session name (Recommended):
This is just a label used locally on your own machine.
I went with
coiai
for this one.
Feel free to use whatever name you like.
SSO Start URL
SSO start URL
Enter your IAM Identity Center access portal URL.
Example
https://d-xxxxxxxx.awsapps.com/start
You can find this URL under
IAM Identity Center
→ Settings
in the console.
SSO Region
SSO region
Specify the region where you enabled IAM Identity Center.
Since mine is the Tokyo region, I set it to
ap-northeast-1
here.
Registration Scope
SSO registration scopes
I kept the default
sso:account:access
as-is.
You generally won't need to change this.
Browser authentication
Partway through, your browser will open automatically,
and log you in to IAM Identity Center.
Once authentication succeeds,
the AWS CLI fetches the AWS accounts available to it.
In my case, it showed
The only AWS account available to you is:
120896952796
as the result.
It also showed
AdministratorAccess
as the available Permission Set.
Region and output format
Next, for
Default client Region
I set
ap-northeast-1
as the value.
And for
CLI default output format
I chose
json
.
JSON plays nicely with Terraform and scripts, so I'd recommend it.
Profile Name
Finally, set a
CLI profile name
.
I named mine
coiai-dev
.
You'll use this name whenever you invoke the AWS CLI.
Verifying the connection
Finally, I ran
aws sts get-caller-identity --profile coiai-dev
.
Here's the result.
{
"UserId": "AROAXXXXXXXXX:Hattori",
"Account": "120896952796",
"Arn": "arn:aws:sts::120896952796:assumed-role/AWSReservedSSO_AdministratorAccess_xxxxxxxxx/Hattori"
}
The important part here is
assumed-role/AWSReservedSSO_AdministratorAccess
.
This means you're being authenticated by assuming an IAM role issued from an IAM Identity Center Permission Set — not by an IAM user.
In other words, I'm logging in to the AWS CLI without using any long-lived access keys at all.
This works directly with Terraform too
In Terraform, you only need to specify this profile to use it.
provider "aws" {
profile = "coiai-dev"
region = "ap-northeast-1"
}
Since the CLI and Terraform share the same credentials, there's no need to write access keys into your code.
What's next
At this point, the authentication foundation for human access to AWS is complete.
Going forward, I'll manage infrastructure as code along this chain:
Developer
│
IAM Identity Center
│
AWS CLI
│
Terraform
│
Dev Account
.
After that, I plan to integrate GitHub Actions with OIDC, building an environment where CI/CD — not just humans — can authenticate securely too.
Wrap-up
Connecting IAM Identity Center with the AWS CLI let me achieve a setup where:
- No access keys are issued
- Temporary credentials are used instead
- It integrates securely with Terraform too
- It follows the authentication approach AWS itself recommends
That's the setup I now have in place.
With AWS Organizations, IAM Identity Center, and the AWS CLI all lined up, I'll now move on to building an Infrastructure as Code environment centered on Terraform.
