invoke AWS api gateway with boto3 assumed_role session

Viewed 25

I created a way to assume role to different accounts on my local machine in order to have their AWS resources available for debugging.

I created multiple local aws profiles like so (in .aws/config):

[default]
aws_access_key_id = {KEY}
aws_secret_access_key ={SECRET}
region = us-east-1

[profile {AWS_PROFILE_NAME}]
role_arn = {ROLE_ARN}
source_profile = default
role_session_name = {SESSSION_NAME}
region = us-east-1

I use boto3 session to assume_role into these accounts based on the AWS_PROFILE variable like so:

def get_session():
    if os.environ['ENV'] == 'local':
        return boto3.session.Session(profile_name=os.getenv('AWS_PROFILE', 'default'))
    return boto3

I tested this and it works fine. To make sure, I can run this:

boto3_session = get_session()
sqs_resource = boto3_session.resource('sqs')
all_queues = sqs_resource.queues.all()

and I have the relevant queues for the current AWS_PROFILE.

Now the issue is when I try to use this session to authenticate api calls using requests like shown in the answer to this question. And also tried:

auth = BotoAWSRequestsAuth(
    aws_host={URL_TO_API_GATEWAY},
    aws_region=region,
    aws_service="execute-api"
)
requests.get(cls._build_service_url(service_name, request_path), auth=auth)

I get 401 Unauthorized whenever I try to invoke a lambda with the assume role.

How can I invoke the API Gateway with the assumed role session (which I made sure works properly)?

0 Answers
Related