Omid Sayfun
Omid SayfunComputer Geek
Home
Notebook
Journey

Online

Github
Linkedin
Hevy
Plyatomic
Notebook
The trap of making everything dynamic
March 01, 2024
A try at type-safe groupBy function in TypeScript
April 10, 2025
Email special headers
November 20, 2024
Adding prettier to eslint
April 10, 2025
Storing Vector in Postgres with Drizzle ORM
March 21, 2024
Upgrading my blog to Next 15
April 05, 2025
Canvas macOS issue
February 20, 2024
tsx doesn’t support decorators
March 26, 2025
Validating NestJS env vars with zod
February 06, 2025
Extending Window: types vs interfaces
March 21, 2025
Loading env file into Node process
February 06, 2025
Add update date field to Postgres
February 27, 2024
Using node API for delay
February 06, 2025
React Component Lifecycle
November 28, 2024
How CQRS is different than Event Sourcing
August 18, 2024
RabbitMQ exchange vs queue
August 14, 2024
PgVector similarity search distance functions
August 13, 2024
PgVector indexing options for vector similarity search
July 31, 2024
Using puppeteer executable for GSTS
June 08, 2024
Why EQ is Your Next Career Upgrade
May 13, 2024
Counting GPT tokens
June 30, 2024
Logging route handler responses in Next.js 14
June 19, 2024
Redirect www subdomain with Cloudflare
June 17, 2024
Logging requests in Express app
June 16, 2024
Move Docker volume to bind mount
June 12, 2024
Next.js Hydration Window Issue
May 29, 2024
Using Git rebase without creating chaos in your repo
May 16, 2024
Implementing RPC Calls with RabbitMQ in TypeScript
March 16, 2024
Optimize webpage load with special tags
March 15, 2024
What the hell is Open Graph?
March 13, 2024
My go-to Next.js ESlint config
March 10, 2024
List of useful Chrome args
March 10, 2024
Combining RxJS observables - Part 1
February 20, 2024

Using puppeteer executable for GSTS

June 08, 2024 · Updated on July 24, 2024

I've been using GSTS for a while now, and it's been a game-changer. It lets you use Google Workspace as a credential provider for your AWS CLI, using browser automation for authentication. If you're in an organization where you need to manage multiple AWS accounts, Google Workspace SAML federation for login credentials validation is super handy. Here's how to get started:

First, install GSTS:

npm install --global gsts

Then, add this credential_process to your ~/.aws/config and you're good to go:

[default]
credential_process = gsts --idp-id=<your_idp_id> --sp-id=<your_sp_id> --aws-role-arn=arn:aws:iam::111111112222222:role/role-name

The issue

When I first set this up and tried to login, I found out that GSTS uses MS Playwright to open a browser and handle the authentication. I got an error that looked something like this:

Error when retrieving credentials from custom-process: [...] ERROR gsts: browserType.launchPersistentContext: Executable doesn't exist at [...]/Caches/ms-playwright/chromium-1105/chrome-mac/Chromium.app/Contents/MacOS/Chromium
╔═════════════════════════════════════════════════════════════════════════╗
║ Looks like Playwright Test or Playwright was just installed or updated. ║





Continue Reading

║ Please run the following command to download new browsers: ║
║ ║
║ npx playwright install ║
║ ║
║ <3 Playwright Team ║
╚═════════════════════════════════════════════════════════════════════════╝

The solution

I already had Puppeteer installed for some automation processes, and I prefer working with that instead of installing Playwright just for this one thing. Turns out, you can add --playwright-engine-executable-path /opt/homebrew/bin/chromium to the end of the credential command:

[profile sts]
credential_process = gsts --idp-id=<your_idp_id> --sp-id=<your_sp_id> --aws-role-arn=arn:aws:iam::111111112222222:role/role-name  --playwright-engine-executable-path /opt/homebrew/bin/chromium

This way, you can use your existing Chromium installation and avoid setting up Playwright separately.

TL;DR

GSTS simplifies using Google Workspace as a credential provider for AWS CLI, especially when managing multiple AWS accounts. Installation is straightforward, but you might encounter a hiccup with Playwright during the first-time setup. A quick fix is to use Puppeteer if you have it already installed, saving you the hassle of setting up another browser automation tool.

  • 02-20-2026

    The trap of making everything dynamic

  • 04-11-2025

    A try at type-safe groupBy function in TypeScript

  • 04-10-2025

    Email special headers

  • 04-10-2025

    Adding prettier to eslint

  • 04-09-2025

    Storing Vector in Postgres with Drizzle ORM