AWS CLI giving InvalidClientTokenId error when Ansible is running well

Viewed 8035

I have the following set-up:

  1. A script updatecreds.py runs, which updates AWS credentials in my Ansible creds file using STS.
  2. Now, I took those creds to run AWS-related tasks in Ansible, and they run smoothly. But, the CLI commands give me an error.
  3. When I use the same credentials in the ~/.aws/config file, I get the following error when executing CLI commands: A client error (InvalidClientTokenId) occurred when calling the ListAccessKeys operation: The security token included in the request is invalid.

As some of my Ansible tasks run shell commands which are AWS cli commands, this behaviour is messing with my Ansible run too.

Why is AWS behaving so weirdly? Or did I do something wrong here?

PS : My ~/.aws/config looks like this:

[default]
aws_access_key_id=<>
aws_secret_access_key=<>
aws_session_token=<>
region=us-east-1
2 Answers
Related