I created a way to assume role to different accounts on my local machine in order to have their AWS resources available for debugging.
I created multiple local aws profiles like so (in .aws/config):
[default]
aws_access_key_id = {KEY}
aws_secret_access_key ={SECRET}
region = us-east-1
[profile {AWS_PROFILE_NAME}]
role_arn = {ROLE_ARN}
source_profile = default
role_session_name = {SESSSION_NAME}
region = us-east-1
I use boto3 session to assume_role into these accounts based on the AWS_PROFILE variable like so:
def get_session():
if os.environ['ENV'] == 'local':
return boto3.session.Session(profile_name=os.getenv('AWS_PROFILE', 'default'))
return boto3
I tested this and it works fine. To make sure, I can run this:
boto3_session = get_session()
sqs_resource = boto3_session.resource('sqs')
all_queues = sqs_resource.queues.all()
and I have the relevant queues for the current AWS_PROFILE.
Now the issue is when I try to use this session to authenticate api calls using requests like shown in the answer to this question. And also tried:
auth = BotoAWSRequestsAuth(
aws_host={URL_TO_API_GATEWAY},
aws_region=region,
aws_service="execute-api"
)
requests.get(cls._build_service_url(service_name, request_path), auth=auth)
I get 401 Unauthorized whenever I try to invoke a lambda with the assume role.
How can I invoke the API Gateway with the assumed role session (which I made sure works properly)?