673b9fc3317d48a169fe612575186b3eb1a42a13

Author
Mark Keisler <mark@mitsein.net>
Committer
GitHub <noreply@github.com>
Date

Message

feat(aws)!: improve `aws_change_access_key` (#11378)

BREAKING CHANGE: This commit removes compatibility for `aws` cli v1. Now only v2 is supported.

Diff

 1diff --git a/plugins/aws/README.md b/plugins/aws/README.md
 2index 846bf1414b04f0d4eab9454ac809a7c520dbfd65..54bc7a44d9f969d6444991fd50c0bb5b366a9e48 100644
 3--- a/plugins/aws/README.md
 4+++ b/plugins/aws/README.md
 5@@ -1,7 +1,8 @@
 6 # aws
 7 
 8-This plugin provides completion support for [awscli](https://docs.aws.amazon.com/cli/latest/reference/index.html)
 9+This plugin provides completion support for [awscli v2](https://awscli.amazonaws.com/v2/documentation/api/latest/reference/index.html)
10 and a few utilities to manage AWS profiles/regions and display them in the prompt.
11+[awscli v1](https://docs.aws.amazon.com/cli/latest/userguide/cliv2-migration.html) is no longer supported.
12 
13 To use it, add `aws` to the plugins array in your zshrc file.
14 
15@@ -12,9 +13,9 @@ plugins=(... aws)
16 ## Plugin commands
17 
18 * `asp [<profile>]`: sets `$AWS_PROFILE` and `$AWS_DEFAULT_PROFILE` (legacy) to `<profile>`.
19-  It also sets `$AWS_EB_PROFILE` to `<profile>` for the Elastic Beanstalk CLI. It sets `$AWS_PROFILE_REGION` for display in `aws_prompt_info`. 
20+  It also sets `$AWS_EB_PROFILE` to `<profile>` for the Elastic Beanstalk CLI. It sets `$AWS_PROFILE_REGION` for display in `aws_prompt_info`.
21   Run `asp` without arguments to clear the profile.
22-* `asp [<profile>] login`: If AWS SSO has been configured in your aws profile, it will run the `aws sso login` command following profile selection. 
23+* `asp [<profile>] login`: If AWS SSO has been configured in your aws profile, it will run the `aws sso login` command following profile selection.
24 
25 * `asr [<region>]`: sets `$AWS_REGION` and `$AWS_DEFAULT_REGION` (legacy) to `<region>`.
26   Run `asr` without arguments to clear the profile.
27@@ -65,7 +66,7 @@ the current `$AWS_PROFILE` and `$AWS_REGION`. It uses four variables to control
28 
29 Source profile credentials in `~/.aws/credentials`:
30 
31-```
32+```ini
33 [source-profile-name]
34 aws_access_key_id = ...
35 aws_secret_access_key = ...
36@@ -73,7 +74,7 @@ aws_secret_access_key = ...
37 
38 Role configuration in `~/.aws/config`:
39 
40-```
41+```ini
42 [profile source-profile-name]
43 mfa_serial = arn:aws:iam::111111111111:mfa/myuser
44 region = us-east-1
45diff --git a/plugins/aws/aws.plugin.zsh b/plugins/aws/aws.plugin.zsh
46index a379eaa18517dee05cbcffa22da90a36a88ee860..d45abba571fb6f80d534f90d82faf446d871cc31 100644
47--- a/plugins/aws/aws.plugin.zsh
48+++ b/plugins/aws/aws.plugin.zsh
49@@ -160,14 +160,39 @@ function aws_change_access_key() {
50     return 1
51   fi
52 
53-  echo "Insert the credentials when asked."
54-  asp "$1" || return 1
55-  AWS_PAGER="" aws iam create-access-key
56-  AWS_PAGER="" aws configure --profile "$1"
57+  local profile="$1"
58+  # Get current access key
59+  local original_aws_access_key_id="$(aws configure get aws_access_key_id --profile $profile)"
60+
61+  asp "$profile" || return 1
62+  echo "Generating a new access key pair for you now."
63+  if aws --no-cli-pager iam create-access-key; then
64+    echo "Insert the newly generated credentials when asked."
65+    aws --no-cli-pager configure --profile $profile
66+  else
67+    echo "Current access keys:"
68+    aws --no-cli-pager iam list-access-keys
69+    echo "Profile \"${profile}\" is currently using the $original_aws_access_key_id key. You can delete an old access key by running \`aws --profile $profile iam delete-access-key --access-key-id AccessKeyId\`"
70+    return 1
71+  fi
72 
73-  echo "You can now safely delete the old access key running \`aws iam delete-access-key --access-key-id ID\`"
74+  read -q "yn?Would you like to disable your previous access key (${original_aws_access_key_id}) now? "
75+  case $yn in
76+    [Yy]*)
77+      echo -n "\nDisabling access key ${original_aws_access_key_id}..."
78+      if aws --no-cli-pager update-access-key --access-key-id ${original_aws_access_key_id} --status Inactive; then
79+        echo "done."
80+      else
81+        echo "\nFailed to disable ${original_aws_access_key_id} key."
82+      fi
83+      ;;
84+    *)
85+      echo ""
86+      ;;
87+  esac
88+  echo "You can now safely delete the old access key by running \`aws --profile $profile iam delete-access-key --access-key-id ${original_aws_access_key_id}\`"
89   echo "Your current keys are:"
90-  AWS_PAGER="" aws iam list-access-keys
91+  aws --no-cli-pager iam list-access-keys
92 }
93 
94 function aws_regions() {