Skip to main content

atmos.aws

The atmos.aws function runs atmos aws through the current Atmos executable. Use it to configure EKS kubeconfig files, log in to Amazon ECR, and generate compliance and security reports from automation.

Usage​

atmos.aws(
*positionals,
flags = {},
args = [],
working_directory = ...,
env = ...,
output = "stream",
check = True,
)

Subcommands​

Pass the subcommand, its nested subcommand, and any positional arguments as strings before the keyword arguments. The call atmos.aws("eks", "update-kubeconfig", flags = {"name": "dev-cluster"}) runs atmos aws eks update-kubeconfig --name=dev-cluster.

SubcommandPurpose
eks update-kubeconfigUpdate the kubeconfig for an EKS cluster.
eks tokenGenerate an EKS bearer token for kubectl.
ecr loginLog in to Amazon ECR registries and write Docker credentials.
compliance reportGenerate a compliance posture report against a framework such as CIS or PCI DSS.
security analyzeAnalyze AWS security findings and map them to Atmos components.

See the atmos aws command reference for the complete list of subcommands and flags. The groups eks, compliance, and security each have their own page.

Arguments​

*positionals

(Optional) Strings placed on the command line right after aws, in order: the subcommand group, the nested subcommand, and any positional arguments. Every value must be a string.

flags

(Optional) A dictionary of command-line options; see flag translation. A bare key such as "region" becomes --region, and registered shorthands resolve to their long form, so "i" resolves to --identity and "s" to --stack. Other flags include --name and --kubeconfig for eks update-kubeconfig, --registry for ecr login, and --framework and --format for compliance report.

args

(Optional) A list or tuple of strings appended after the flags. The aws command accepts a -- separator before arguments meant for the underlying tool.

working_directory, env, output, check

(Optional) See atmos.run for process options and defaults.

Options other than the positionals are keyword-only.

Returns​

A result with stdout, stderr, and exit_code. See atmos.run for output and error behavior.

Examples​

Configure kubectl for an EKS cluster​

atmos.aws(
"eks",
"update-kubeconfig",
flags = {"name": "dev-cluster", "region": "us-east-2", "identity": "dev-admin"},
)

This runs atmos aws eks update-kubeconfig --identity=dev-admin --name=dev-cluster --region=us-east-2.

Log in to ECR before a build​

atmos.aws("ecr", "login", flags = {"identity": "dev-admin", "registry": ["123456789012.dkr.ecr.us-east-2.amazonaws.com"]})

Save a compliance report​

report = atmos.aws(
"compliance",
"report",
flags = {"stack": "plat-ue2-prod", "framework": "cis-aws", "format": "json"},
output = "capture",
)
data = json.decode(report.stdout)
print(data)

Write security findings to a file​

atmos.aws(
"security",
"analyze",
flags = {"stack": "plat-ue2-prod", "severity": "critical,high", "format": "sarif", "file": "findings.sarif"},
)

The security commands require aws.security.enabled: true in atmos.yaml. Without it the call fails with an error that names the setting.