NAME
aws-iam-ra - get credentials from AWS IAM Roles Anywhere
USAGE
aws-iam-ra [--help] [--man] [--usage] [--version]
aws-iam-ra --certificate|-c <path>
[--duration|-d <duration-in-sec>]
[--full]
--key|-k <path>
[--key-type|-K <RSA|ECDSA>]
--profile-arn|-p <string>
--region|-R <region-name>
--role-arn|-r <string>
--trust-anchor-arn|-t <string>
EXAMPLES
aws-iam-ra \
--certificate /path/to/certificate.pem \
--key /path/to/key.pem \
--profile-arn 'arn:aws:rolesanywhere:eu-south-1:1234:profile/12...' \
--role-arn 'arn:aws:iam::1234:role/test1234...' \
--trust-anchor 'arn:aws:rolesanywhere:eu-south-1:1234:trust-anc...' \
--region eu-south-1
DESCRIPTION
Program to fetch credentials for assuming a specific role using AWS IAM Roles Anywhere. It's meant as a replacement for aws_credential_helper.
It's basically everything in the example.
You can restrict the duration by providing option --duration, use a value that is at least 900 or you will get an error.
By default it prints out only the credentials; you can use --full to print the whole response from AWS.
The key type is assumed to be RSA by default. Set it to ECDSA in case you are using the other type.
CONFIGURATION
Most of the command-line parameters can be set using environment variables:
CERT_FILEcorresponds to--certificate|-cDURATIONcorresponds to--duration|-dKEY_FILEcorresponds to--key|-kKEY_TYPEcorresponds to--key-type|-KPROFILE_ARNcorresponds to--profile-arn|-pREGIONcorresponds to--region|-RROLE_ARNcorresponds to--role-arn|-rTRUST_ANCHOR_ARNcorresponds to--trust-anchor-arn|-t
When set, command-line parameters take precedence over environment variables.
AUTHOR
Flavio Poletti flavio@polettix.it.
LICENSE AND COPYRIGHT
Copyright 2026 by Flavio Poletti flavio@polettix.it.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
or look for file LICENSE in this project's root directory.
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.