atmos ai skill install atmos-authAtmos Authentication and Identity Management
Atmos Auth provides a unified authentication layer for multiple cloud providers. It consolidates AWS SSO, SAML,
OIDC, GitHub Actions, GCP Workload Identity Federation, Azure, Atmos Pro, and static credentials into a single configuration
model in atmos.yaml. Credentials are managed through providers (upstream authentication systems) and identities
(the roles and accounts obtained from those providers), with support for identity chaining, keyring-based
credential storage, and integrations like ECR, EKS, and GitHub STS.
Architecture Overview
The auth system has four layers configured under the auth: key in atmos.yaml:
- Providers -- Upstream systems that issue initial credentials (SSO, SAML, OIDC, GCP ADC/WIF).
- Identities -- Roles, permission sets, or accounts obtained from providers or chained from other identities.
- Keyring -- Secure credential storage backend (system keyring, encrypted file, or in-memory).
- Integrations -- Client-side credential materializations (ECR Docker login, EKS kubeconfig, GitHub STS).
auth:logs:level: Info # Debug, Info, Warn, Errorfile: /path/to/auth.log # Optional log filekeyring:type: system # system, file, or memoryproviders:<name>:kind: <provider-kind># Provider-specific fieldsidentities:<name>:kind: <identity-kind># Identity-specific fieldsintegrations:<name>:kind: aws/ecr# Integration-specific fields
Related Skills
| Need | Load |
|---|---|
| Atmos Pro setup, uploads, workflow dispatch, drift detection | atmos-pro |
| Private GitHub remote imports and component source | atmos-imports |
| Native CI using OIDC | atmos-ci |
| GitOps repositories and signed commits | atmos-git |
Provider Types
AWS IAM Identity Center (SSO)
The most common provider for AWS organizations. Requires kind, region, and start_url.
auth:providers:company-sso:kind: aws/iam-identity-centerregion: us-east-1start_url: https://company.awsapps.com/startauto_provision_identities: true # Auto-discover accounts and permission setssession:duration: 4hconsole:session_duration: 12h # Web console session (max 12h)
When auto_provision_identities: true, Atmos queries sso:ListAccounts and sso:ListAccountRoles during
login to automatically create identities for all assigned permission sets.
AWS SAML
For SAML-based IdPs (Okta, Google Apps, ADFS). The next identity in the chain must be aws/assume-role.
auth:providers:okta-saml:kind: aws/samlregion: us-east-1url: https://company.okta.com/app/amazon_aws/abc123/sso/samldriver: Browser # Browser, GoogleApps, Okta, or ADFS
GitHub Actions OIDC
For CI/CD pipelines in GitHub Actions. Requires id-token: write permission in the workflow.
Use this through a CI profile selected with ATMOS_PROFILE.
auth:providers:github-oidc:kind: github/oidcregion: us-east-1spec:audience: sts.us-east-1.amazonaws.com # Optional, defaults to STS endpoint
The cloud IAM trust policy must constrain GitHub OIDC sub claims to the intended repository
and branch or GitHub environment, for example repo:ORG/REPO:ref:refs/heads/main or
repo:ORG/REPO:environment:prod.
Atmos Pro Provider
Use kind: atmos/pro when the Atmos CLI needs to authenticate to Atmos Pro, including
github/sts token minting.
auth:providers:atmos-pro:kind: atmos/prospec:workspace_id: !env ATMOS_PRO_WORKSPACE_IDidentities:atmos-pro:kind: atmos/provia:provider: atmos-pro
In GitHub Actions, this uses the runner OIDC token. Grant permissions.id-token: write.
GCP Application Default Credentials
For local development using existing gcloud authentication. Requires gcloud auth application-default login.
auth:providers:gcp-adc:kind: gcp/adcproject_id: my-gcp-project # Optional, defaults to gcloud configregion: us-central1 # Optionalscopes:- https://www.googleapis.com/auth/cloud-platform
GCP Workload Identity Federation
For CI/CD using OIDC tokens. In GitHub Actions, token_source is auto-detected from environment variables.
auth:providers:gcp-wif:kind: gcp/workload-identity-federationproject_id: my-gcp-projectproject_number: "123456789012"workload_identity_pool_id: github-poolworkload_identity_provider_id: github-providerservice_account_email: ci-sa@my-project.iam.gserviceaccount.com
For non-GitHub environments, configure token_source explicitly with type (url, file, or environment),
the source location, audience, and allowed_hosts.
Identity Types
AWS Permission Set
Maps to an SSO permission set on a specific account. Use principal.account.name (resolved via SSO) or
principal.account.id (direct).
auth:identities:dev-admin:kind: aws/permission-setdefault: truevia:provider: company-ssoprincipal:name: AdminAccessaccount:name: development
AWS Assume Role
Assumes an IAM role, either directly from a provider or chained from another identity.
auth:identities:prod-admin:kind: aws/assume-rolevia:identity: base-admin # Chain from another identityprincipal:assume_role: arn:aws:iam::999999999999:role/ProductionAdminsession_name: atmos-prod # Optional, for CloudTrail auditing
AWS Assume Root
Centralized root access in AWS Organizations using sts:AssumeRoot. Limited to 15-minute sessions.
auth:identities:root-audit:kind: aws/assume-rootvia:identity: admin-baseprincipal:target_principal: "123456789012"task_policy_arn: arn:aws:iam::aws:policy/root-task/IAMAuditRootUserCredentialsduration: 15m
Supported task policies: IAMAuditRootUserCredentials, IAMCreateRootUserPassword,
IAMDeleteRootUserCredentials, S3UnlockBucketPolicy, SQSUnlockQueuePolicy.
AWS User (Break-glass)
Static IAM user credentials for emergency access. Use !env to reference environment variables.
auth:identities:emergency:kind: aws/usercredentials:access_key_id: !env EMERGENCY_AWS_ACCESS_KEY_IDsecret_access_key: !env EMERGENCY_AWS_SECRET_ACCESS_KEYregion: us-east-1mfa_arn: arn:aws:iam::123456789012:mfa/username # Optional MFA
Azure Subscription
Targets a specific Azure subscription. Sets AZURE_SUBSCRIPTION_ID, ARM_SUBSCRIPTION_ID, etc.
auth:identities:dev-subscription:kind: azure/subscriptionvia:provider: azure-cliprincipal:subscription_id: "12345678-1234-1234-1234-123456789012"location: eastusresource_group: my-rg
GCP Service Account
Impersonates a GCP service account. Requires roles/iam.serviceAccountTokenCreator on the base identity.
auth:identities:terraform:kind: gcp/service-accountdefault: truevia:provider: gcp-adcprincipal:service_account_email: terraform@my-project.iam.gserviceaccount.comproject_id: my-projectlifetime: 3600s
GCP Project
Sets GCP project context. Sets GOOGLE_CLOUD_PROJECT, CLOUDSDK_CORE_PROJECT, GOOGLE_CLOUD_REGION.
auth:identities:prod-project:kind: gcp/projectvia:provider: gcp-adcprincipal:project_id: production-projectregion: us-central1zone: us-central1-a
Identity Chaining
Chains can be arbitrarily deep: provider -> identity -> identity -> ... -> identity. Use via.provider to
start from a provider or via.identity to chain from another identity. They are mutually exclusive. Circular
dependencies are detected and rejected.
auth:identities:base-admin:kind: aws/permission-setvia:provider: company-ssoprincipal:name: AdminAccessaccount:name: core-identityprod-admin:kind: aws/assume-rolevia:identity: base-adminprincipal:assume_role: arn:aws:iam::999999999999:role/ProductionAdminprod-readonly:kind: aws/assume-rolevia:identity: prod-adminprincipal:assume_role: arn:aws:iam::999999999999:role/ReadOnlyAccess
Keyring Backends
| Type | Persistence | Security | Use Case |
|---|---|---|---|
system | Yes | High (OS-managed) | Interactive workstations (Keychain, GNOME Keyring, Windows Credential Manager) |
file | Yes | Medium (AES-256 encrypted) | Headless servers, Docker containers, CI/CD |
memory | No | Low (in-process) | Testing, temporary sessions |
File keyring password resolution: ATMOS_KEYRING_PASSWORD env var, then interactive prompt, then error.
Commands Quick Reference
| Command | Purpose |
|---|---|
atmos auth login [--identity <name>] | Authenticate with SSO/SAML/OIDC/static credentials |
atmos auth whoami [--identity <name>] | Show current authentication status |
atmos auth validate [--verbose] | Validate auth configuration for syntax and logic errors |
atmos auth shell [--identity <name>] | Launch interactive shell with credentials pre-configured |
atmos auth exec [--identity <name>] -- <cmd> | Execute a single command with identity credentials |
atmos auth env [--format bash|json|dotenv] | Export credentials as environment variables |
atmos auth console [--destination <url>] | Open cloud provider web console in browser |
atmos auth list [--format table|tree|json|yaml|graphviz|mermaid] | List providers and identities |
atmos auth ecr-login [integration] | Login to AWS ECR registries |
atmos auth logout [identity] [--all] [--provider] | Clear cached credentials |
All commands accepting --identity support three modes: with value (use that identity), without value
(interactive selector), or omitted (use default or prompt). The -i alias works for all.
Disabling Authentication
Disable Atmos-managed auth to use native cloud provider credentials:
atmos terraform plan mycomponent --stack=dev --identity=false
Or:
export ATMOS_IDENTITY=false
Recognized disable values: false, 0, no, off (case-insensitive).
CI/CD Integration
GitHub Actions with OIDC
jobs:deploy:permissions:id-token: writecontents: readenv:ATMOS_PROFILE: githubsteps:- uses: actions/checkout@v6- run: atmos terraform deploy mycomponent -s prod
For AWS OIDC, configure github/oidc provider with aws/assume-role identity. For GCP WIF, configure
gcp/workload-identity-federation provider -- token_source is auto-detected in GitHub Actions.
Do not add a routine atmos auth login step to non-interactive OIDC workflows; Atmos exchanges
the OIDC token when the command runs.
Disabling Auth in CI
When the CI platform provides credentials natively:
env:ATMOS_IDENTITY: falserun: atmos terraform apply mycomponent --stack=prod
Profiles for Environment Switching
Use Atmos profiles to swap provider and identity configurations while keeping names consistent. For profile directory layout, activation, and merge behavior, load atmos-profiles:
atmos --profile developer terraform plan myapp -s devATMOS_PROFILE=ci atmos terraform apply myapp -s prod
Keep this skill focused on the auth sections inside a profile, such as providers, identities, and keyring settings.
ECR Integrations
ECR integrations auto-trigger on identity login when auto_provision: true (default):
auth:integrations:dev/ecr:kind: aws/ecrvia:identity: dev-adminspec:auto_provision: trueregistry:account_id: "123456789012"region: us-east-2
Integration failures are non-blocking during atmos auth login. Use atmos auth ecr-login to retry.
GitHub STS Integration
Use kind: github/sts to mint short-lived, least-privilege GitHub App tokens through Atmos Pro.
This is the preferred CI path for private GitHub vendoring, component source:, remote import:,
Terraform private modules, atmos git, and other Git subprocesses.
auth:providers:atmos-pro:kind: atmos/prospec:workspace_id: !env ATMOS_PRO_WORKSPACE_IDidentities:atmos-pro:kind: atmos/provia:provider: atmos-prointegrations:github-sts:kind: github/stsvia:provider: atmos-prospec:auto_provision: truerepos: [acme/modules]policy_name: defaultgit_config_mode: envrevoke_on_exit: truetoken_env: ATMOS_PRO_GITHUB_TOKEN
In CI, github/sts can auto-provision lazily before the first private remote read when
atmos/pro plus github/sts are configured and auto_provision is not disabled. The same minted
credentials cover atmos vendor pull, remote import:, component source:, private Terraform
module fetches, and managed Git operations. ATMOS_PRO_GITHUB_TOKEN is preferred for Atmos-native
Git reads ahead of ATMOS_GITHUB_TOKEN and GITHUB_TOKEN.
Environment Variables
| Variable | Purpose |
|---|---|
ATMOS_IDENTITY | Default identity name, or false to disable auth |
ATMOS_KEYRING_TYPE | Override keyring backend (system, file, memory) |
ATMOS_KEYRING_PASSWORD | Password for file keyring |
ATMOS_XDG_CONFIG_HOME | Override config directory for AWS files |
ATMOS_XDG_DATA_HOME | Override data directory for file keyring |
ATMOS_PRO_WORKSPACE_ID | Atmos Pro workspace ID for atmos/pro |
ATMOS_PRO_BASE_URL | Override Atmos Pro base URL |
ATMOS_PRO_GITHUB_TOKEN | Preferred token for Atmos-native Git reads minted by github/sts |
Security Best Practices
- Never commit credentials to version control. Use
!env VAR_NAMEfor sensitive values. - Use shortest practical session durations for high-security environments.
- Validate configurations regularly with
atmos auth validate. - Use identity chaining with least-privilege roles rather than broad permissions.
- Logout when switching contexts or ending sessions:
atmos auth logout. - Browser sessions with IdPs remain active after local logout -- sign out from the IdP separately.
Additional Resources
- references/providers-and-identities.md -- Detailed provider and identity configuration patterns
- references/commands-reference.md -- Complete command reference for all auth subcommands