Diff
1diff --git a/plugins/aws/README.md b/plugins/aws/README.md
2index 4ceb71425639c251e8f1b2f5a2a84b3788c2ba1d..851f586ddd12935da9037af3539327fd2a250bb4 100644
3--- a/plugins/aws/README.md
4+++ b/plugins/aws/README.md
5@@ -15,6 +15,13 @@ plugins=(... aws)
6 It also sets `$AWS_EB_PROFILE` to `<profile>` for the Elastic Beanstalk CLI.
7 Run `asp` without arguments to clear the profile.
8
9+* `acp [<profile>]`: in addition to `asp` functionality, it actually changes the profile by
10+ assuming the role specified in the `<profile>` configuration. It supports MFA and sets
11+ `$AWS_ACCESS_KEY_ID`, `$AWS_SECRET_ACCESS_KEY` and `$AWS_SESSION_TOKEN`, if obtained. It
12+ requires the roles to be configured as per the
13+ [official guide](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-role.html).
14+ Run `acp` without arguments to clear the profile.
15+
16 * `agp`: gets the current value of `$AWS_PROFILE`.
17
18 * `aws_change_access_key`: changes the AWS access key of a profile.
19diff --git a/plugins/aws/aws.plugin.zsh b/plugins/aws/aws.plugin.zsh
20index fe1f098e80b02e6807c03339d76b6837374b2ca7..8149ba12116f65635d479aa074f7d91f0887a0e6 100644
21--- a/plugins/aws/aws.plugin.zsh
22+++ b/plugins/aws/aws.plugin.zsh
23@@ -4,6 +4,27 @@ function agp() {
24
25 # AWS profile selection
26 function asp() {
27+ if [[ -z "$1" ]]; then
28+ unset AWS_DEFAULT_PROFILE AWS_PROFILE AWS_EB_PROFILE
29+ echo AWS profile cleared.
30+ return
31+ fi
32+
33+ local -a available_profiles
34+ available_profiles=($(aws_profiles))
35+ if [[ -z "${available_profiles[(r)$1]}" ]]; then
36+ echo "${fg[red]}Profile '$1' not found in '${AWS_CONFIG_FILE:-$HOME/.aws/config}'" >&2
37+ echo "Available profiles: ${(j:, :)available_profiles:-no profiles found}${reset_color}" >&2
38+ return 1
39+ fi
40+
41+ export AWS_DEFAULT_PROFILE=$1
42+ export AWS_PROFILE=$1
43+ export AWS_EB_PROFILE=$1
44+}
45+
46+# AWS profile switch
47+function acp() {
48 if [[ -z "$1" ]]; then
49 unset AWS_DEFAULT_PROFILE AWS_PROFILE AWS_EB_PROFILE AWS_ACCESS_KEY_ID AWS_SECRET_ACCESS_KEY AWS_SESSION_TOKEN
50 echo AWS profile cleared.
51@@ -34,7 +55,7 @@ function asp() {
52 echo "Please enter the session duration in seconds (900-43200; default: 3600, which is the default maximum for a role):"
53 read sess_duration
54 if [[ -z $sess_duration ]]; then
55- sess_duration = 3600
56+ sess_duration="3600"
57 fi
58 mfa_opt="--serial-number $mfa_serial --token-code $mfa_token --duration-seconds $sess_duration"
59 fi
60@@ -100,6 +121,7 @@ function _aws_profiles() {
61 reply=($(aws_profiles))
62 }
63 compctl -K _aws_profiles asp aws_change_access_key
64+compctl -K _aws_profiles acp aws_change_access_key
65
66 # AWS prompt
67 function aws_prompt_info() {