aws cli ๋ถ€๋™๐Ÿ˜ญ ํ•  ๋•Œ ํ•ด๋ณด์„ธ์š”. [์ˆ˜์‹œ๋กœ ์—…๋ฐ์ดํŠธ]

1781 ๋‹จ์–ด AWStech

์บ์‹œ ๋ฐ ํ™˜๊ฒฝ ๋ณ€์ˆ˜์— ๋Œ€ํ•œ ์„ธ์…˜ ํ† ํฐ์„ ์ œ๊ฑฐํ•˜์‹ญ์‹œ์˜ค.


rm -f ~/.aws/cli/cache/*
unset AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN

AWS์˜ API๋ฅผ ๋‘๋“œ๋ฆฌ๊ธฐ ์œ„ํ•ด ์„ค์ •๋œ ์ธ์ฆ ์ •๋ณด๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.


aws configure list

# ใ‚นใ‚คใƒƒใƒใƒญใƒผใƒซใ‚ใ‚Šใฎๅ ดๅˆ
aws configure list --profile ${PROFILE}
์ฐธ์กฐ: https://dev.classmethod.jp/cloud/aws/how-to-configure-aws-cli/

์ธ์ฆ ์ •๋ณด๋ฅผ ๋ฐ›๋Š” ์‚ฌ์šฉ์ž ํ™•์ธ


์„ค์ •
aws sts get-caller-identity

# ใ‚นใ‚คใƒƒใƒใƒญใƒผใƒซใ‚ใ‚Šใฎๅ ดๅˆ
aws sts get-caller-identity --profile ${PROFILE}
awscli-aliasํ›„aws whoamiํ•˜๋ฉด ํ˜ธ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ฐธ์กฐ: https://dev.classmethod.jp/cloud/aws/aws-cli-alias/

์„ค์ •๋œ IAM ์ •์ฑ… ๊ฒ€ํ† 


aws iam list-attached-user-policies --user-name ${USERNAME} --query "AttachedPolicies[*].PolicyArn" --output text | xargs -n1 -I {} aws iam get-policy --policy-arn {}

aws iam get-policy-version \
  --policy-arn <โ†‘ใงๅ–ๅพ—ใ—ใŸIAMใƒใƒชใ‚ทใƒผใฎARN> \
  --version-id <โ†‘ใงๅ–ๅพ—ใ—ใŸใƒใƒผใ‚ธใƒงใƒณID>

# ใ‚นใ‚คใƒƒใƒใƒญใƒผใƒซใ™ใ‚‹ๅ ดๅˆ
PROFILE=YOUR_PROFILE
ROLE_NAME=YOUR_ROLE_NAME
aws iam list-attached-role-policies --role-name ${ROLE_NAME} --profile ${PROFILE} --query "AttachedPolicies[*].PolicyArn" --output text | xargs -n1 -I {} aws iam get-policy --policy-arn {} --profile ${PROFILE}

aws iam get-policy-version \
  --policy-arn <โ†‘ใงๅ–ๅพ—ใ—ใŸIAMใƒใƒชใ‚ทใƒผใฎARN> \
  --version-id <โ†‘ใงๅ–ๅพ—ใ—ใŸใƒใƒผใ‚ธใƒงใƒณID> \
  --profile=${PROFILE}

์ข‹์€ ์›นํŽ˜์ด์ง€ ์ฆ๊ฒจ์ฐพ๊ธฐ