GSTS lets you use Google Workspace as a credential provider for your AWS CLI. It drives a browser in the background to complete the SAML login, then writes short-lived credentials for the role you asked for. If you manage multiple AWS accounts in one organization, Google Workspace SAML federation validates the login for all of them, so the AWS CLI SAML login is the same flow everywhere.
First, install GSTS:
npm install --global gstsThen add this credential_process line to your ~/.aws/config:
[default]
credential_process = gsts --idp-id=<your_idp_id> --sp-id=<your_sp_id> --aws-role-arn=arn:aws:iam::111111112222222:role/role-nameGSTS uses MS Playwright to open a browser and handle the authentication. On my first login it failed, because Playwright had never downloaded a browser on that machine. The error looked like this:
Error when retrieving credentials from custom-process: [...] ERROR gsts: browserType.launchPersistentContext: Executable doesn't exist at [...]/Caches/ms-playwright/chromium-1105/chrome-mac/Chromium.app/Contents/MacOS/Chromium
╔═════════════════════════════════════════════════════════════════════════╗
║ Looks like Playwright Test or Playwright was just installed or updated. ║
║ Please run the following command to download new browsers: ║
║ ║
║ npx playwright install ║
║ ║
║ <3 Playwright Team ║
╚═════════════════════════════════════════════════════════════════════════╝The message tells you to run npx playwright install, which downloads a second browser. I already had Puppeteer installed for some automation processes, and I prefer working with that instead of installing Playwright for this one thing. GSTS takes a flag for the browser binary, so you can pass any Chromium executable path: the one from puppeteer.executablePath(), or the Homebrew Chromium on macOS. Add --playwright-engine-executable-path /opt/homebrew/bin/chromium to the end of the credential command:
[profile sts]
credential_process = gsts --idp-id=<your_idp_id> --sp-id=<your_sp_id> --aws-role-arn=arn:aws:iam::111111112222222:role/role-name --playwright-engine-executable-path /opt/homebrew/bin/chromiumThis way, you can use your existing Chromium installation and avoid setting up Playwright separately.
GSTS lets you use Google Workspace as a credential provider for the AWS CLI, which helps when you manage several AWS accounts. The first-time setup can fail on Playwright. If you already have Puppeteer installed, point GSTS at its browser instead of installing another one.
Occasional notes on software, tools, and things I learn. No spam.
Unsubscribe anytime.