atmos.aws
The atmos.aws function runs atmos aws through the current Atmos executable. Use it to configure EKS
kubeconfig files, log in to Amazon ECR, and generate compliance and security reports from automation.
Usage
atmos.aws(
*positionals,
flags = {},
args = [],
working_directory = ...,
env = ...,
output = "stream",
check = True,
)
Subcommands
Pass the subcommand, its nested subcommand, and any positional arguments as strings before the keyword arguments.
The call atmos.aws("eks", "update-kubeconfig", flags = {"name": "dev-cluster"}) runs
atmos aws eks update-kubeconfig --name=dev-cluster.
| Subcommand | Purpose |
|---|---|
eks update-kubeconfig | Update the kubeconfig for an EKS cluster. |
eks token | Generate an EKS bearer token for kubectl. |
ecr login | Log in to Amazon ECR registries and write Docker credentials. |
compliance report | Generate a compliance posture report against a framework such as CIS or PCI DSS. |
security analyze | Analyze AWS security findings and map them to Atmos components. |
See the atmos aws command reference for the complete list of subcommands and flags. The
groups eks, compliance, and
security each have their own page.
Arguments
*positionals(Optional) Strings placed on the command line right after
aws, in order: the subcommand group, the nested subcommand, and any positional arguments. Every value must be a string.flags(Optional) A dictionary of command-line options; see flag translation. A bare key such as
"region"becomes--region, and registered shorthands resolve to their long form, so"i"resolves to--identityand"s"to--stack. Other flags include--nameand--kubeconfigforeks update-kubeconfig,--registryforecr login, and--frameworkand--formatforcompliance report.args(Optional) A list or tuple of strings appended after the flags. The
awscommand accepts a--separator before arguments meant for the underlying tool.working_directory,env,output,check(Optional) See
atmos.runfor process options and defaults.
Options other than the positionals are keyword-only.
Returns
A result with stdout, stderr, and exit_code. See atmos.run for output and error behavior.
Examples
Configure kubectl for an EKS cluster
atmos.aws(
"eks",
"update-kubeconfig",
flags = {"name": "dev-cluster", "region": "us-east-2", "identity": "dev-admin"},
)
This runs atmos aws eks update-kubeconfig --identity=dev-admin --name=dev-cluster --region=us-east-2.
Log in to ECR before a build
atmos.aws("ecr", "login", flags = {"identity": "dev-admin", "registry": ["123456789012.dkr.ecr.us-east-2.amazonaws.com"]})
Save a compliance report
report = atmos.aws(
"compliance",
"report",
flags = {"stack": "plat-ue2-prod", "framework": "cis-aws", "format": "json"},
output = "capture",
)
data = json.decode(report.stdout)
print(data)
Write security findings to a file
atmos.aws(
"security",
"analyze",
flags = {"stack": "plat-ue2-prod", "severity": "critical,high", "format": "sarif", "file": "findings.sarif"},
)
The security commands require aws.security.enabled: true in atmos.yaml. Without it the call fails with an
error that names the setting.
Related
atmos.runruns any Atmos command from an argument list.atmos awsdocuments every subcommand and flag.- Atmos Automation Language and the script step