API Reference
pdum.aws
AWS utils.
Small, reusable helpers over boto3:
- :mod:
pdum.aws.core— sessions and clients on the ambient credential chain. - :mod:
pdum.aws.secrets— a namespaced view of SSM Parameter Store. - :mod:
pdum.aws.quotas— inspect Service Quotas and request increases. - :mod:
pdum.aws.env— build a process environment from.envand SSM.
Nothing here hardcodes a profile, region, or account. Credentials come from
boto3's own resolution, so an account is selected by setting
AWS_PROFILE in the environment:
$ AWS_PROFILE=my-account python -m my_script
from pdum import aws
print(aws.whoami()["Account"])
A script that wants the environment pdx would have given it — the project's
.env, its .env.local overlay, and the secrets on the SSM search path —
calls :func:~pdum.aws.env.load_env in place of dotenv.load_dotenv():
from pdum.aws import load_env
load_env()
EnvReport
dataclass
What :func:load_env did, layer by layer.
Attributes:
| Name | Type | Description |
|---|---|---|
env_files |
LoadReport or None
|
What the |
path |
str
|
The SSM search path that was used. |
path_source |
str
|
Where that path came from, for reporting. |
secrets |
LoadReport
|
What the store contributed. |
Source code in src/pdum/aws/env.py
163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 | |
NoSearchPath
Bases: LookupError
No SSM search path could be resolved, so no secrets could be loaded.
Raised rather than passed over: a process that quietly continues without the secrets it asked for fails later, somewhere less informative.
Source code in src/pdum/aws/env.py
131 132 133 134 135 136 | |
client(service, region=None)
Create a service client on the ambient credential chain.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service
|
str
|
Service name, e.g. |
required |
region
|
str
|
Region to pin the client to. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
Any
|
A |
Source code in src/pdum/aws/core.py
54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 | |
load_env(*, environ=None, env_file='.env', envvar=DEFAULT_ENVVAR, default_path=None, store_factory=SecretStore)
Load the project's .env files and its secrets into the environment.
The drop-in for dotenv.load_dotenv() in a project that keeps its secrets
in SSM. Layers are applied most-specific-last-wins-least: whatever is
already set stays, then the .env pair fills gaps, then the store fills
what remains. See the module docstring for why the order matters.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
environ
|
mutable mapping
|
Environment to update; defaults to |
None
|
env_file
|
str
|
File to search for upward from the working directory, and the base name
of the |
".env"
|
envvar
|
str
|
Variable naming the SSM search path. |
DEFAULT_ENVVAR
|
default_path
|
str or callable
|
Search path to fall back on when the environment, including the
|
None
|
store_factory
|
callable
|
Called with the resolved path to build the store. Override to pin a
region, e.g. |
:class:`~pdum.aws.secrets.SecretStore`
|
Returns:
| Type | Description |
|---|---|
EnvReport
|
What each layer contributed. Ignore it for the common case; it is there for reporting and for tests. |
Raises:
| Type | Description |
|---|---|
NoSearchPath
|
If no search path could be resolved. Loading a |
ValueError
|
If the resolved path is not a usable SSM prefix — a root path, say. |
Source code in src/pdum/aws/env.py
391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 | |
resource(service, region=None)
Create a service resource on the ambient credential chain.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service
|
str
|
Service name, e.g. |
required |
region
|
str
|
Region to pin the resource to. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
Any
|
A |
Source code in src/pdum/aws/core.py
72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 | |
session(region=None)
Create a session on the ambient credential chain.
A fresh :class:boto3.Session is created per call rather than reusing
boto3's module-level default session, which caches the credentials it
resolved on first use. Building a new one keeps each call honest about the
current environment — it picks up a re-exported AWS_PROFILE or a
refreshed SSO token instead of serving stale credentials for the life of the
process.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
region
|
str
|
Region to pin the session to. When |
None
|
Returns:
| Type | Description |
|---|---|
Session
|
A session bound to whatever credentials the environment provides. |
Source code in src/pdum/aws/core.py
30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 | |
whoami(region=None)
Return the identity the current credentials resolve to.
Useful as a cheap credential check before doing anything destructive, and as the fastest way to confirm which account is actually in play.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
region
|
str
|
Region for the STS call. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
dict of str to str
|
The |
Source code in src/pdum/aws/core.py
90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 | |
pdum.aws.core
Ambient AWS sessions and clients.
This module deliberately knows nothing about named profiles. boto3 already
resolves credentials from AWS_PROFILE, AWS_ACCESS_KEY_ID /
AWS_SECRET_ACCESS_KEY, SSO token caches, ECS/EC2 instance roles and
~/.aws/config — so the correct behaviour for a reusable library is to let it,
and to select an account by setting AWS_PROFILE in the environment:
$ AWS_PROFILE=my-account python -m my_script
Nothing here hardcodes a profile, a region, or an account. A library that picks a default profile is a library that silently talks to the wrong account when it is reused somewhere else.
Region is likewise left to boto3, which reads AWS_REGION,
AWS_DEFAULT_REGION and the profile's region. Pass region= only for
APIs that are pinned to one region regardless of where the caller lives — Route
53 Domains and CloudFront ACM certificates being the usual examples.
client(service, region=None)
Create a service client on the ambient credential chain.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service
|
str
|
Service name, e.g. |
required |
region
|
str
|
Region to pin the client to. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
Any
|
A |
Source code in src/pdum/aws/core.py
54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 | |
resource(service, region=None)
Create a service resource on the ambient credential chain.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service
|
str
|
Service name, e.g. |
required |
region
|
str
|
Region to pin the resource to. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
Any
|
A |
Source code in src/pdum/aws/core.py
72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 | |
session(region=None)
Create a session on the ambient credential chain.
A fresh :class:boto3.Session is created per call rather than reusing
boto3's module-level default session, which caches the credentials it
resolved on first use. Building a new one keeps each call honest about the
current environment — it picks up a re-exported AWS_PROFILE or a
refreshed SSO token instead of serving stale credentials for the life of the
process.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
region
|
str
|
Region to pin the session to. When |
None
|
Returns:
| Type | Description |
|---|---|
Session
|
A session bound to whatever credentials the environment provides. |
Source code in src/pdum/aws/core.py
30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 | |
whoami(region=None)
Return the identity the current credentials resolve to.
Useful as a cheap credential check before doing anything destructive, and as the fastest way to confirm which account is actually in play.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
region
|
str
|
Region for the STS call. See :func: |
None
|
Returns:
| Type | Description |
|---|---|
dict of str to str
|
The |
Source code in src/pdum/aws/core.py
90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 | |
pdum.aws.secrets
Secrets in AWS SSM Parameter Store, resolved along a search path.
A :class:SecretStore is built from a search path of SSM prefixes, most
specific first — "/myapp/:/org/" — and maps a name like STRIPE_KEY
onto the parameter <prefix>STRIPE_KEY in each layer. Reads resolve in this
order:
- a real environment variable of that name, so a shell export, a
.envloaded by the caller, or a test fixture can override without touching AWS; - each SSM prefix in path order (decrypted), first hit wins;
- the supplied
default, or a :class:KeyErrorwhenrequired=True.
Layered prefixes work like layered config files (project, then org, then global): a project stores only what is truly its own and inherits the rest, so a secret shared by many projects lives in exactly one place. Writes and deletes always target the first prefix — the layer the store belongs to — never a fallback layer; mutating a shared layer requires constructing a store whose path starts there.
Why Parameter Store rather than Secrets Manager: standard-tier parameters are free where Secrets Manager is roughly $0.40 per secret per month, and both give KMS encryption, IAM gating and CloudTrail audit. This module is the only thing that knows which backend is in use, so switching later is a one-file change.
The path is required and has no default — a shared default would let two
unrelated projects collide in the same namespace, and would make
:meth:SecretStore.names return parameters the caller does not own.
from pdum.aws.secrets import SecretStore
store = SecretStore("/myapp/:/org/")
store.put("STRIPE_KEY", "sk_live_...") # written to /myapp/STRIPE_KEY
store.get("GOOGLE_CLIENT_ID") # found at /org/GOOGLE_CLIENT_ID
This module does not read .env files, and nothing here touches the
filesystem as a side effect of being imported. Env-first resolution looks at
os.environ only. When you want the .env layer too, call
:func:pdum.aws.env.load_env explicitly — it applies the files and then this
store, in that order, and returns a report of what each contributed.
SecretStore
A namespaced view of SSM Parameter Store, layered along a search path.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
path
|
str or sequence of str
|
SSM search path, most specific prefix first: a colon-separated string
( |
required |
region
|
str
|
Region for the SSM client. When |
None
|
Attributes:
| Name | Type | Description |
|---|---|---|
prefixes |
tuple of str
|
The normalised search path, each element leading- and trailing-slashed. |
Source code in src/pdum/aws/secrets.py
112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 | |
prefix
property
The first prefix on the path — the layer writes and deletes target.
ssm
property
The SSM client, created lazily on first use.
Deferred so that constructing a store, or resolving a secret that is already present in the environment, never requires credentials.
clear_cache()
Drop cached values so the next read goes back to SSM.
Needed when another process has rotated a secret during this one's lifetime.
Source code in src/pdum/aws/secrets.py
386 387 388 389 390 391 392 | |
delete(name)
Delete a secret from the write layer and drop it from the cache.
Only the first prefix is ever deleted from. When the name exists solely in a fallback layer, this raises rather than reaching down: deleting from a shared layer must be asked for explicitly, with a store whose path starts there.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Secret name without a prefix. |
required |
Raises:
| Type | Description |
|---|---|
KeyError
|
If the secret is not in the write layer. The message names the fallback layer holding it, when there is one. |
Source code in src/pdum/aws/secrets.py
276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 | |
describe()
List metadata for each secret on the search path.
Deliberately does not decrypt: this reads names, types and timestamps only, so rendering a listing never pulls secret values over the wire.
Returns:
| Type | Description |
|---|---|
list of dict
|
One dict per parameter per layer, with |
Source code in src/pdum/aws/secrets.py
352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 | |
get(name, *, default=None, required=False)
Resolve a secret from the environment, then each prefix, then default.
Successful and missing lookups are both cached for the life of the store, so repeated reads cost one walk of the path at most.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Secret name without a prefix. |
required |
default
|
str
|
Returned when the secret exists nowhere and |
None
|
required
|
bool
|
Raise instead of returning default when the secret is missing. |
False
|
Returns:
| Type | Description |
|---|---|
str or None
|
The secret value, or default when absent. |
Raises:
| Type | Description |
|---|---|
KeyError
|
If the secret is missing and |
Source code in src/pdum/aws/secrets.py
183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 | |
get_json(name, *, default=None, required=False)
Resolve a secret and parse it as JSON.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Secret name without a prefix. |
required |
default
|
Any
|
Returned when the secret is absent and |
None
|
required
|
bool
|
Raise instead of returning default when the secret is missing. |
False
|
Returns:
| Type | Description |
|---|---|
Any
|
The parsed JSON value, or default when absent. |
Raises:
| Type | Description |
|---|---|
KeyError
|
If the secret is missing and |
JSONDecodeError
|
If the stored value is not valid JSON. |
Source code in src/pdum/aws/secrets.py
228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 | |
names()
List the secret names visible to this store, without prefixes.
Names present in several layers appear once.
Returns:
| Type | Description |
|---|---|
list of str
|
Secret names, unsorted. |
Source code in src/pdum/aws/secrets.py
311 312 313 314 315 316 317 318 319 320 321 | |
path(name)
Return the full SSM parameter path for name in the write layer.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Secret name without a prefix. |
required |
Returns:
| Type | Description |
|---|---|
str
|
The full path, e.g. |
Source code in src/pdum/aws/secrets.py
156 157 158 159 160 161 162 163 164 165 166 167 168 169 | |
put(name, value, *, secure=True)
Create or overwrite a secret in the write layer, updating the cache.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Secret name without a prefix. |
required |
value
|
str
|
Value to store. |
required |
secure
|
bool
|
Store as a KMS-encrypted |
True
|
Source code in src/pdum/aws/secrets.py
255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 | |
read_all()
Read every secret on the search path in one pass, first layer winning.
Costs one paginated call per layer rather than one call per name, which
is what makes materialising a whole store — into a process environment,
say — cheap enough to do on every invocation. Unlike :meth:describe
this decrypts, so it does pull values over the wire.
The environment is deliberately not consulted, unlike :meth:get:
this is the store's own view, leaving the caller to decide how it should
interact with variables that are already set.
Values are cached as if each name had been fetched individually, so a
later :meth:get for any of them costs nothing.
Returns:
| Type | Description |
|---|---|
dict of str to str
|
Secret name to value, shadowed layers excluded. |
Source code in src/pdum/aws/secrets.py
323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 | |
pdum.aws.env
Building a process environment from .env files and SSM, in layers.
This is what pdx does, available to any script that wants the same
environment without being launched under it:
from pdum.aws import load_env
load_env() # os.environ now carries the project's variables and its secrets
Use it where you would otherwise call dotenv.load_dotenv(). It does strictly
more: the same .env handling, plus the .env.local overlay, plus the
secrets from the SSM search path that the .env usually names.
Three layers, most specific first
- the environment you already have — never overwritten, so a variable exported for one run wins, and a CI job's injected variables are never undone;
- the nearest
.env, overlaid with an adjacent.env.local— searched for upward from the working directory, so this works from anywhere inside a project. The whole file is loaded, not just the SSM path: a project's.envis whereAWS_PROFILEandAWS_REGIONlive too, and without those the store cannot be reached at all. That is why these are applied before the store is opened; - the SSM store, on the search path named by
PDUM_SSM_PATH— which is itself usually set by that.env.
Nothing here runs on import. :mod:pdum.aws.secrets says that a library must
not read .env behind a plain import, and that still holds — this module
provides the function and lets the application decide when to call it. Being
explicit is also what makes the ordering above something you can rely on.
.env and .env.local
Only .env is searched for; the overlay is taken from beside whatever was
found, never searched for separately, so one directory always wins and there is
never a question of which .env.local applies. A .env.local with no
.env to anchor it is ignored.
The two are read as one document rather than as two dicts to merge, so that
a ${VAR} in the local file can refer to a name defined in the committed one
— which is most of the point of having a local file. Merging parsed results
would leave that reference unresolved.
Parsing goes through python-dotenv rather than a hand-rolled KEY=VALUE
split, because the format has more corners than it appears to: export
prefixes, inline comments, single versus double quoting, and quoted values
spanning several lines. A naive split reads
PDUM_SSM_PATH=/myapp/:/org/ # the project's own layer
as a prefix with a comment glued onto the end, and SSM would take that at face value.
Interpolation of ${VAR} is the caller's choice, because the two callers want
opposite things. Loading an environment should expand, as every other .env
consumer does. secrets import should not: a value on its way into permanent
storage must arrive exactly as written, or the password p@ss${word}word
silently becomes p@ssword and nothing records that it ever said more.
EnvReport
dataclass
What :func:load_env did, layer by layer.
Attributes:
| Name | Type | Description |
|---|---|---|
env_files |
LoadReport or None
|
What the |
path |
str
|
The SSM search path that was used. |
path_source |
str
|
Where that path came from, for reporting. |
secrets |
LoadReport
|
What the store contributed. |
Source code in src/pdum/aws/env.py
163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 | |
LoadReport
dataclass
What one layer contributed to the environment.
Attributes:
| Name | Type | Description |
|---|---|---|
source |
str
|
Where the values came from, for reporting: a file path, or a search path. |
applied |
list of str
|
Names this layer set. |
already_set |
list of str
|
Names it offered that the environment already had, so were kept. A more specific layer had already won. |
skipped |
list of str
|
Names unusable as environment variables, e.g. a nested |
Source code in src/pdum/aws/env.py
139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 | |
NoSearchPath
Bases: LookupError
No SSM search path could be resolved, so no secrets could be loaded.
Raised rather than passed over: a process that quietly continues without the secrets it asked for fails later, somewhere less informative.
Source code in src/pdum/aws/env.py
131 132 133 134 135 136 | |
find_env_file(name='.env')
Find name in the working directory or the nearest ancestor holding one.
Searching upward is what lets this run from anywhere inside a project and
still find that project's file, the way git finds its repository. A
name with a directory component is taken literally instead, so an explicit
config/.env is never second-guessed.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
File name to search for, or a path to use as given. |
".env"
|
Returns:
| Type | Description |
|---|---|
Path or None
|
The file found, or |
Source code in src/pdum/aws/env.py
227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 | |
find_env_files(name='.env')
Find name and its adjacent .local overlay, least specific first.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
File name to search for, or a path to use as given. |
".env"
|
Returns:
| Type | Description |
|---|---|
list of pathlib.Path
|
Empty when name was not found, otherwise the file and, if it exists,
its |
Source code in src/pdum/aws/env.py
254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 | |
is_env_name(name)
Whether name can be used as an environment variable.
A store may hold nested parameters, whose names carry a slash — a secret at
/myapp/db/PASSWORD is named db/PASSWORD. Exporting that would make a
variable no program could name, so such names are reported and skipped
rather than set.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
name
|
str
|
Candidate variable name. |
required |
Returns:
| Type | Description |
|---|---|
bool
|
True when a shell could name it. |
Source code in src/pdum/aws/env.py
110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 | |
load_env(*, environ=None, env_file='.env', envvar=DEFAULT_ENVVAR, default_path=None, store_factory=SecretStore)
Load the project's .env files and its secrets into the environment.
The drop-in for dotenv.load_dotenv() in a project that keeps its secrets
in SSM. Layers are applied most-specific-last-wins-least: whatever is
already set stays, then the .env pair fills gaps, then the store fills
what remains. See the module docstring for why the order matters.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
environ
|
mutable mapping
|
Environment to update; defaults to |
None
|
env_file
|
str
|
File to search for upward from the working directory, and the base name
of the |
".env"
|
envvar
|
str
|
Variable naming the SSM search path. |
DEFAULT_ENVVAR
|
default_path
|
str or callable
|
Search path to fall back on when the environment, including the
|
None
|
store_factory
|
callable
|
Called with the resolved path to build the store. Override to pin a
region, e.g. |
:class:`~pdum.aws.secrets.SecretStore`
|
Returns:
| Type | Description |
|---|---|
EnvReport
|
What each layer contributed. Ignore it for the common case; it is there for reporting and for tests. |
Raises:
| Type | Description |
|---|---|
NoSearchPath
|
If no search path could be resolved. Loading a |
ValueError
|
If the resolved path is not a usable SSM prefix — a root path, say. |
Source code in src/pdum/aws/env.py
391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 | |
load_env_files(env_file, environ)
Apply the nearest .env, and its .local overlay, to environ.
Every variable in the files is loaded, not only the SSM search path. Call this before opening a store, or the store may be opened against the wrong account, or no account at all — see the module docstring.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
env_file
|
str
|
File name to search for upward from the working directory, or a path with a directory component to use as given. |
required |
environ
|
mutable mapping
|
Environment to update, normally |
required |
Returns:
| Type | Description |
|---|---|
LoadReport or None
|
What the files contributed, or |
Source code in src/pdum/aws/env.py
298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 | |
load_secrets(store, environ)
Apply store to environ, in one bulk read, keeping what is already set.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
store
|
SecretStore
|
Store to read. |
required |
environ
|
mutable mapping
|
Environment to update, normally |
required |
Returns:
| Type | Description |
|---|---|
LoadReport
|
What the store contributed. |
Source code in src/pdum/aws/env.py
326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 | |
no_search_path_message(envvar, env_file, found)
Explain every way the search path could have been supplied.
Source code in src/pdum/aws/env.py
383 384 385 386 387 388 | |
read_env_file(path, *, interpolate=True)
Read one .env file. See :func:read_env_files.
Source code in src/pdum/aws/env.py
222 223 224 | |
read_env_files(paths, *, interpolate=True)
Read several .env files as though they were one, later files winning.
The files are concatenated and parsed once, so interpolation reaches across them and a repeated name resolves the way a repeated name inside a single file does — the last one wins.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
paths
|
sequence of pathlib.Path or str
|
Files to read, least specific first. |
required |
interpolate
|
bool
|
Expand |
True
|
Returns:
| Type | Description |
|---|---|
dict of str to str
|
Names mapped to values. A bare name declared with no |
Source code in src/pdum/aws/env.py
191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 | |
resolve_search_path(*, envvar=DEFAULT_ENVVAR, default_path=None, environ, env_file_report=None)
Work out which SSM search path to use, and say where it came from.
Call after :func:load_env_files, so that a path set by a file is already
in environ and needs no separate lookup — it is one environment variable
among all the others by this point. env_file_report is used only to
describe the source precisely.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
envvar
|
str
|
Variable holding the path. |
DEFAULT_ENVVAR
|
default_path
|
str or callable
|
Fallback when the environment has none; a callable is resolved here. |
None
|
environ
|
mapping
|
Environment to consult, normally |
required |
env_file_report
|
LoadReport
|
Result of :func: |
None
|
Returns:
| Type | Description |
|---|---|
tuple of (str or None, str)
|
The path, and a short description of its source for reporting. |
Source code in src/pdum/aws/env.py
344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 | |
pdum.aws.quotas
Service Quotas: inspect current limits and request increases.
A fresh AWS account can launch almost nothing — typically 5 vCPUs of standard on-demand EC2 and zero of every accelerator family. Raising that is a per-region, per-quota request process with several non-obvious traps, which this module encodes.
from pdum.aws import quotas
statuses = quotas.report(quotas.EC2_VCPU_TARGETS, region="us-east-1")
for s in statuses:
print(s.target.label, s.current, s.state)
results = quotas.submit(quotas.EC2_VCPU_TARGETS, region="us-east-1")
Functions here return data and never print, so callers own presentation.
Things that surprise people
EC2 quotas count vCPUs, not instances. "I want 4 GPUs" becomes "I want 768
vCPUs of P", because p5.48xlarge is 192 vCPUs. Convert through the instance
type you actually intend to run.
Instance generation is not a quota dimension. P spans p3 (V100), p4
(A100) and p5 (H100); G spans g4dn (T4), g5 (A10G), g6 (L4) and g6e (L40S).
Old and new hardware cannot be requested separately.
Nor is CPU architecture. Graviton (c7g, c8g, m7g, r7g) draws
from the Standard pool, whose name lists instance-family letters
(A, C, D, H, I, M, R, T, Z), not architectures — the A is a1, not "ARM".
Quota is a ceiling, not a commitment — and not capacity. Holding a large
quota costs nothing, so asking high has no downside but refusal. But an approved
P quota does not mean p5 will launch; on-demand H100 is frequently
unavailable regardless of quota, and Capacity Blocks for ML is the mechanism
that actually reserves that class of hardware.
Rate limits on requesting
Two meta-quotas govern the requests themselves:
L-36BDD542"Active requests per quota" is 1, so an in-flight request cannot be revised — you wait for it to be decided.- An undocumented account-wide cap of :data:
ACCOUNT_OPEN_REQUEST_CAPopen requests, which is not readable from any API and surfaces only asQuotaExceededException. It held at exactly 20 on two separate accounts.
So a large batch cannot be submitted in one sitting. :func:submit stops
cleanly at the cap and is idempotent, making the workflow: submit, wait for
cases to be decided, submit again.
Looking up quota codes
Never hand-type a quota code; a wrong one is a wasted support case.
$ aws service-quotas list-service-quotas --service-code ec2 \
--query 'Quotas[].[QuotaCode,QuotaName,Value]' --output text
Note that list-service-quotas returns only quotas with an applied value,
so ones never modified can be missing. Use list-aws-default-service-quotas
to enumerate the full catalogue, and check Adjustable before requesting —
some quotas cannot be raised at all.
QuotaRequest
dataclass
One quota-increase request as Service Quotas recorded it.
Attributes:
| Name | Type | Description |
|---|---|---|
code |
str
|
Quota code the request targets. |
name |
str
|
Human-readable quota name from the API. |
desired |
float
|
Value that was asked for. |
status |
str
|
|
request_id |
str or None
|
Service Quotas request id. |
case_id |
str or None
|
Support case id, present once a request has been escalated to a human. |
created |
datetime or None
|
When the request was raised. |
last_updated |
datetime or None
|
When it last changed status. |
Source code in src/pdum/aws/quotas.py
164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 | |
is_approved
property
Whether this request was granted.
An unapproved request does not imply the quota is unchanged. AWS also
raises quotas on young accounts automatically, independently of any
request — observed raising standard EC2 vCPU limits in a region where no
request had been submitted at all. Always compare against the applied
value from :func:current_values rather than inferring it from status.
is_open
property
Whether this request still awaits a decision.
QuotaStatus
dataclass
Where one quota stands relative to its target.
Attributes:
| Name | Type | Description |
|---|---|---|
target |
QuotaTarget
|
The quota and desired value. |
current |
float or None
|
Currently applied value, or |
pending_value |
float or None
|
Desired value of an in-flight request, if any. |
pending_status |
str or None
|
Status of that in-flight request, e.g. |
Source code in src/pdum/aws/quotas.py
119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 | |
has_open_request
property
Whether a request for this quota is awaiting a decision.
needs_submit
property
Whether this quota still needs a request raised.
satisfied
property
Whether the applied value already meets the target.
state
property
A one-word summary: satisfied, open or to-submit.
QuotaTarget
dataclass
A quota and the value to request for it.
Attributes:
| Name | Type | Description |
|---|---|---|
label |
str
|
Human-readable name, used only for display. |
code |
str
|
Service Quotas code, e.g. |
value |
float
|
Desired value. For EC2 compute quotas this is a vCPU count. |
Source code in src/pdum/aws/quotas.py
100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 | |
SubmitResult
dataclass
The outcome of trying to raise one quota.
Attributes:
| Name | Type | Description |
|---|---|---|
target |
QuotaTarget
|
The quota that was attempted. |
outcome |
str
|
One of |
request_id |
str or None
|
Service Quotas request id, when one was created. |
request_status |
str or None
|
Status the request came back with, typically |
error |
str or None
|
Error message when |
Source code in src/pdum/aws/quotas.py
216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 | |
current_values(targets, *, service_code='ec2', region=None)
Look up the currently applied value for each target's quota.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
targets
|
list of QuotaTarget
|
Quotas to look up. |
required |
service_code
|
str
|
Service Quotas service code. |
"ec2"
|
region
|
str
|
Region to query. Quotas are per-region. |
None
|
Returns:
| Type | Description |
|---|---|
dict of str to (float or None)
|
Quota code mapped to its applied value, or |
Source code in src/pdum/aws/quotas.py
246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 | |
open_requests(*, service_code='ec2', region=None)
Find quota-increase requests that are still awaiting a decision.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service_code
|
str
|
Service Quotas service code. |
"ec2"
|
region
|
str
|
Region to query. |
None
|
Returns:
| Type | Description |
|---|---|
dict of str to tuple
|
Quota code mapped to |
Source code in src/pdum/aws/quotas.py
321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 | |
report(targets, *, service_code='ec2', region=None)
Describe where each target stands, without changing anything.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
targets
|
list of QuotaTarget
|
Quotas to inspect. |
required |
service_code
|
str
|
Service Quotas service code. |
"ec2"
|
region
|
str
|
Region to query. |
None
|
Returns:
| Type | Description |
|---|---|
list of QuotaStatus
|
One entry per target, in the order given. |
Source code in src/pdum/aws/quotas.py
343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 | |
request_history(*, service_code='ec2', region=None)
List every quota-increase request, decided or not.
This is how you find out what AWS actually did with a batch: statuses
include APPROVED, DENIED and CASE_CLOSED alongside the open
PENDING and CASE_OPENED.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
service_code
|
str
|
Service Quotas service code. |
"ec2"
|
region
|
str
|
Region to query. |
None
|
Returns:
| Type | Description |
|---|---|
list of QuotaRequest
|
Requests newest-updated first. |
Source code in src/pdum/aws/quotas.py
281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 | |
submit(targets, *, service_code='ec2', region=None, dry_run=False)
Request increases for every target that needs one.
Idempotent: targets already satisfied, or already carrying an open request,
are skipped rather than resubmitted. Stops at the first
QuotaExceededException, since once the account's open-request cap is hit
every subsequent call would fail the same way.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
targets
|
list of QuotaTarget
|
Quotas to raise. |
required |
service_code
|
str
|
Service Quotas service code. |
"ec2"
|
region
|
str
|
Region to act on. |
None
|
dry_run
|
bool
|
Report what would be submitted without calling the write API. |
False
|
Returns:
| Type | Description |
|---|---|
list of SubmitResult
|
One entry per target considered. Iteration stops early on
|
Source code in src/pdum/aws/quotas.py
381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 | |
pdum.aws.cli
pdum-aws — manage SSM secrets and service quotas from the shell.
$ pdum-aws whoami
$ pdum-aws secrets --path /myapp/ list
$ pdum-aws quotas status --region us-east-1
$ pdum-aws pdx-doctor
Installing the package also provides pdx, a short form of pdum-aws pdx:
it loads a project's secrets into the environment and hands the process over to
a command. See :mod:pdum.aws.cli.pdx.
$ pdx npm run dev
Run inside a project, the CLI first loads the nearest .env and its
.env.local overlay — the whole file, exactly as pdx reads it, never
overriding what the shell already set. A project whose .env names
AWS_PROFILE and PDUM_SSM_PATH therefore gets every command bare: no
exports, no flags. Only the files are loaded, never the SSM store — fetching
secrets in order to manage secrets would be circular. pdx and
pdx-doctor are excluded: they assemble the environment themselves and
report where every layer came from, and a pre-loaded .env would blur that
report.
Beyond that, credentials come from the ambient environment, exactly as in the
library. There is deliberately no --profile flag: select an account the
standard way — AWS_PROFILE in the project's .env or in the shell — so
this behaves like every other AWS tool on the box.
$ AWS_PROFILE=my-account pdum-aws quotas status
The secrets commands need a search path — one or more SSM prefixes, colon-
separated, most specific first — which has no default: PDUM_SSM_PATH in
the .env or the shell, or --path per invocation.
add_pdx(app, *, console=None, default_path=None, envvar=DEFAULT_ENVVAR, env_file='.env', store_factory=SecretStore, name='pdx')
Register a pdx command on app.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
app
|
Typer
|
Application to register the command on. |
required |
console
|
Console
|
Console for this command's own diagnostics. Defaults to
:data: |
None
|
default_path
|
str or callable
|
Search path used when the environment, including the |
None
|
envvar
|
str
|
Environment variable holding the search path. |
DEFAULT_ENVVAR
|
env_file
|
str
|
File searched for upward from the working directory, and the base name
of the |
".env"
|
store_factory
|
callable
|
Called with the resolved path to build the store. |
:class:`~pdum.aws.secrets.SecretStore`
|
name
|
str
|
Name to register the command under. |
"pdx"
|
Source code in src/pdum/aws/cli/pdx.py
102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 | |
add_pdx_doctor(app, *, console=None, default_path=None, envvar=DEFAULT_ENVVAR, env_file='.env', store_factory=SecretStore, name='pdx-doctor')
Register a command explaining what :func:add_pdx would do.
Answers the questions secrets list cannot, because they are about this
process rather than about the store: which .env was found and what it
contributed, which search path resolved and from where, and which names the
environment already holds — the reason a program run under pdx can see a
value that is not the one in SSM.
It applies the .env exactly as pdx does, since that is what decides
the account the store is read from. Secrets themselves are reported by name
and layer only: this works from
:meth:~pdum.aws.secrets.SecretStore.describe, which does not decrypt, so
running it pulls no secret value over the wire. Use secrets get when the
value is what you want.
Parameters are as for :func:add_pdx, except that console defaults to
stdout — here the report is the output.
Source code in src/pdum/aws/cli/pdx.py
162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 | |
add_whoami(app, *, console=None, name='whoami')
Register a whoami command on app.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
app
|
Typer
|
Application to register the command on. |
required |
console
|
Console
|
Console to render through; defaults to
:data: |
None
|
name
|
str
|
Name to register the command under, in case the host already has one. |
"whoami"
|
Source code in src/pdum/aws/cli/identity.py
25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 | |
aws_errors(console=None)
Turn credential and API failures into one readable line.
A missing profile or an expired SSO session is the single most common way these commands fail, and a botocore traceback is a poor way to say so. Host applications embedding a group should wrap their own entry point in this to get the same treatment:
def main() -> None:
with aws_errors(my_console):
app()
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console to report through; defaults to :data: |
None
|
Raises:
| Type | Description |
|---|---|
SystemExit
|
With status 2, in place of the original |
Source code in src/pdum/aws/cli/output.py
55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 | |
build_quotas_app(*, console=None, default_service='ec2', default_targets=None, default_regions=None, show_service_option=True, show_targets_option=True, help='Inspect and request AWS service quotas.')
Build a quotas command group.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console every command in the group renders through; defaults to
:data: |
None
|
default_service
|
str
|
Service Quotas service code used when |
"ec2"
|
default_targets
|
list of QuotaTarget or callable
|
Target plan used when |
None
|
default_regions
|
list of str
|
Regions acted on when |
None
|
show_service_option
|
bool
|
Whether |
True
|
show_targets_option
|
bool
|
Whether |
True
|
help
|
str
|
Group help text. |
'Inspect and request AWS service quotas.'
|
Returns:
| Type | Description |
|---|---|
Typer
|
A new application, ready to pass to |
Source code in src/pdum/aws/cli/quotas.py
114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 | |
build_secrets_app(*, console=None, default_path=None, envvar='PDUM_SSM_PATH', expose_path_option=True, store_factory=SecretStore, help='Manage secrets in AWS SSM Parameter Store.')
Build a secrets command group.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console every command in the group renders through; defaults to
:data: |
None
|
default_path
|
str or callable
|
SSM search path to use when neither the flag nor the environment supplies one. Pass a zero-argument callable to defer resolving it — a host reading the path from a config file wants that read to happen on invocation, not on import. |
None
|
envvar
|
str
|
Environment variable consulted before default_path. Pass |
'PDUM_SSM_PATH'
|
expose_path_option
|
bool
|
Whether to offer |
True
|
store_factory
|
callable
|
Called with the resolved path to build the store. Override to thread
host configuration through, e.g.
|
:class:`~pdum.aws.secrets.SecretStore`
|
help
|
str
|
Group help text. |
'Manage secrets in AWS SSM Parameter Store.'
|
Returns:
| Type | Description |
|---|---|
Typer
|
A new application, ready to pass to |
Source code in src/pdum/aws/cli/secrets.py
130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 | |
emit(console, text)
Print text verbatim, as data rather than as a message.
Markup, syntax highlighting and wrapping are all disabled for this one call,
so a secret containing square brackets is never mangled, a long value is
never broken across lines, and piping stays clean. Use this for anything a
caller might redirect into a file or another process; use
console.print directly for messages addressed to a human.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console to write through. |
required |
text
|
str
|
The value to write. |
required |
Source code in src/pdum/aws/cli/output.py
36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 | |
main()
Console-script entry point.
Wraps the app so credential and API problems print one readable line instead of a botocore traceback — a missing profile or an expired SSO session is the single most common way this tool fails.
Source code in src/pdum/aws/cli/__init__.py
139 140 141 142 143 144 145 146 147 | |
pdum.aws.cli.secrets
The secrets command group, as a factory other applications can embed.
:func:build_secrets_app returns a fresh :class:typer.Typer each call, so a
host CLI can mount these commands under its own name, render them through its
own console, and — the point of the exercise — supply the SSM search path its
users should not have to type:
import typer
from pdum.aws.cli import build_secrets_app
app = typer.Typer()
app.add_typer(build_secrets_app(default_path="/acme/:/org/", envvar="ACME_SSM_PATH"), name="secrets")
acme secrets list now works bare. The search path resolves in this order:
--pathon the command line;- the environment variable named by envvar;
- default_path, which may be a callable when the host reads it from a config file and wants that read deferred to invocation time;
- otherwise an error — the library itself ships no default, because a shared one would let unrelated projects collide in one namespace.
A path is one or more SSM prefixes, colon-separated, most specific first —
reads fall back along it, writes and deletes target the first prefix only
(see :mod:pdum.aws.secrets). Pass expose_path_option=False to drop the
flag entirely and pin the namespace to default_path.
build_secrets_app(*, console=None, default_path=None, envvar='PDUM_SSM_PATH', expose_path_option=True, store_factory=SecretStore, help='Manage secrets in AWS SSM Parameter Store.')
Build a secrets command group.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console every command in the group renders through; defaults to
:data: |
None
|
default_path
|
str or callable
|
SSM search path to use when neither the flag nor the environment supplies one. Pass a zero-argument callable to defer resolving it — a host reading the path from a config file wants that read to happen on invocation, not on import. |
None
|
envvar
|
str
|
Environment variable consulted before default_path. Pass |
'PDUM_SSM_PATH'
|
expose_path_option
|
bool
|
Whether to offer |
True
|
store_factory
|
callable
|
Called with the resolved path to build the store. Override to thread
host configuration through, e.g.
|
:class:`~pdum.aws.secrets.SecretStore`
|
help
|
str
|
Group help text. |
'Manage secrets in AWS SSM Parameter Store.'
|
Returns:
| Type | Description |
|---|---|
Typer
|
A new application, ready to pass to |
Source code in src/pdum/aws/cli/secrets.py
130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 | |
store_from(ctx)
Return the store this invocation resolved.
Useful to host applications adding their own commands to a group built by
:func:build_secrets_app, which then read the same search path as the rest.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
ctx
|
Context
|
Context of a command inside the group. |
required |
Returns:
| Type | Description |
|---|---|
SecretStore
|
The store built by the group's callback. |
Source code in src/pdum/aws/cli/secrets.py
71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 | |
pdum.aws.cli.quotas
The quotas command group, as a factory other applications can embed.
:func:build_quotas_app mirrors :func:~pdum.aws.cli.secrets.build_secrets_app:
a fresh :class:typer.Typer per call, rendering through a console the host
supplies, with the defaults its users should not have to type. Where the secrets
group needs a search path, this one needs a service code, a target plan and a
set of regions:
import typer
from pdum.aws.cli import build_quotas_app
app = typer.Typer()
app.add_typer(
build_quotas_app(
default_service="ec2",
default_targets=ACME_GPU_TARGETS,
default_regions=["us-east-1", "us-west-2"],
),
name="quotas",
)
acme quotas status now reports the plan that application cares about, in the
regions it runs in. The flags remain available to override any of it; pass
show_service_option=False / show_targets_option=False to keep them out
of --help when the host's users have no business changing them.
build_quotas_app(*, console=None, default_service='ec2', default_targets=None, default_regions=None, show_service_option=True, show_targets_option=True, help='Inspect and request AWS service quotas.')
Build a quotas command group.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console every command in the group renders through; defaults to
:data: |
None
|
default_service
|
str
|
Service Quotas service code used when |
"ec2"
|
default_targets
|
list of QuotaTarget or callable
|
Target plan used when |
None
|
default_regions
|
list of str
|
Regions acted on when |
None
|
show_service_option
|
bool
|
Whether |
True
|
show_targets_option
|
bool
|
Whether |
True
|
help
|
str
|
Group help text. |
'Inspect and request AWS service quotas.'
|
Returns:
| Type | Description |
|---|---|
Typer
|
A new application, ready to pass to |
Source code in src/pdum/aws/cli/quotas.py
114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 | |
pdum.aws.cli.pdx
pdx — run a command with the project's environment and secrets loaded.
$ pdx npm run dev
$ pdx python -m my_service --port 8080
$ pdx -- ls -la
pdx has no options of its own. Everything after the name is the command
to run, so no flag of yours can collide with one of its own, and -- is
available but never required. The only exception is a leading --help, which
click reserves; pdx python --help still reaches Python, because parsing
stops at the first bare word.
The environment it hands over is built by :func:pdum.aws.env.load_env, in
three layers — what you already have, the nearest .env and its
.env.local overlay, then the SSM store. That module is the place to read
about the ordering and why it matters; this one is only the command around it,
and a script wanting the same environment should call load_env directly
rather than shelling out to pdx.
Then the process is replaced by the command, a real execvp: same PID, so
signals, job control, exit status and the terminal all belong to the program you
asked for, with nothing left in the middle to forward them.
pdx-doctor shows what that adds up to without running anything.
Both commands are attachable, so an application can offer the same thing under its own name and defaults:
from pdum.aws.cli import add_pdx, add_pdx_doctor
add_pdx(app, default_path="/acme/:/org/", envvar="ACME_SSM_PATH")
add_pdx_doctor(app, default_path="/acme/:/org/", envvar="ACME_SSM_PATH")
add_pdx(app, *, console=None, default_path=None, envvar=DEFAULT_ENVVAR, env_file='.env', store_factory=SecretStore, name='pdx')
Register a pdx command on app.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
app
|
Typer
|
Application to register the command on. |
required |
console
|
Console
|
Console for this command's own diagnostics. Defaults to
:data: |
None
|
default_path
|
str or callable
|
Search path used when the environment, including the |
None
|
envvar
|
str
|
Environment variable holding the search path. |
DEFAULT_ENVVAR
|
env_file
|
str
|
File searched for upward from the working directory, and the base name
of the |
".env"
|
store_factory
|
callable
|
Called with the resolved path to build the store. |
:class:`~pdum.aws.secrets.SecretStore`
|
name
|
str
|
Name to register the command under. |
"pdx"
|
Source code in src/pdum/aws/cli/pdx.py
102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 | |
add_pdx_doctor(app, *, console=None, default_path=None, envvar=DEFAULT_ENVVAR, env_file='.env', store_factory=SecretStore, name='pdx-doctor')
Register a command explaining what :func:add_pdx would do.
Answers the questions secrets list cannot, because they are about this
process rather than about the store: which .env was found and what it
contributed, which search path resolved and from where, and which names the
environment already holds — the reason a program run under pdx can see a
value that is not the one in SSM.
It applies the .env exactly as pdx does, since that is what decides
the account the store is read from. Secrets themselves are reported by name
and layer only: this works from
:meth:~pdum.aws.secrets.SecretStore.describe, which does not decrypt, so
running it pulls no secret value over the wire. Use secrets get when the
value is what you want.
Parameters are as for :func:add_pdx, except that console defaults to
stdout — here the report is the output.
Source code in src/pdum/aws/cli/pdx.py
162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 | |
build_pdx_app(**kwargs)
Build a standalone one-command application around :func:add_pdx.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
**kwargs
|
Any
|
Forwarded to :func: |
{}
|
Returns:
| Type | Description |
|---|---|
Typer
|
An application whose only command is |
Source code in src/pdum/aws/cli/pdx.py
241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 | |
main()
Console-script entry point for pdx.
Source code in src/pdum/aws/cli/pdx.py
263 264 265 266 | |
pdum.aws.cli.identity
The whoami command, attachable to any Typer application.
A single command rather than a group, so it is registered onto the host's app directly instead of being added as a sub-app:
import typer
from pdum.aws.cli import add_whoami
app = typer.Typer()
add_whoami(app, name="aws-identity")
add_whoami(app, *, console=None, name='whoami')
Register a whoami command on app.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
app
|
Typer
|
Application to register the command on. |
required |
console
|
Console
|
Console to render through; defaults to
:data: |
None
|
name
|
str
|
Name to register the command under, in case the host already has one. |
"whoami"
|
Source code in src/pdum/aws/cli/identity.py
25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 | |
pdum.aws.cli.output
Console plumbing shared by every command group.
Each group is produced by a factory taking a console, so a host CLI can pass
its own themed :class:~rich.console.Console and have these commands render
through it — one theme, one width, one output stream for the whole application.
Omitting it falls back to :data:DEFAULT_CONSOLE.
from rich.console import Console
from pdum.aws.cli import build_secrets_app
app.add_typer(build_secrets_app(console=Console(stderr=True)), name="secrets")
aws_errors(console=None)
Turn credential and API failures into one readable line.
A missing profile or an expired SSO session is the single most common way these commands fail, and a botocore traceback is a poor way to say so. Host applications embedding a group should wrap their own entry point in this to get the same treatment:
def main() -> None:
with aws_errors(my_console):
app()
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console to report through; defaults to :data: |
None
|
Raises:
| Type | Description |
|---|---|
SystemExit
|
With status 2, in place of the original |
Source code in src/pdum/aws/cli/output.py
55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 | |
emit(console, text)
Print text verbatim, as data rather than as a message.
Markup, syntax highlighting and wrapping are all disabled for this one call,
so a secret containing square brackets is never mangled, a long value is
never broken across lines, and piping stays clean. Use this for anything a
caller might redirect into a file or another process; use
console.print directly for messages addressed to a human.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
console
|
Console
|
Console to write through. |
required |
text
|
str
|
The value to write. |
required |
Source code in src/pdum/aws/cli/output.py
36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 | |