Skip to content

aws login: configurable session length beyond 12 hours for unattended hosts #10738

Description

@heredia21

Describe the feature

Make the aws login session length configurable beyond 12 hours, or provide a supported, non-interactive way to extend it, for hosts that run unattended jobs.

Use Case

aws login is now recommended for coding-agent setups (for example the AWS MCP Server SigV4 path). On a headless host that also runs scheduled read-only checks (cron health reports, monitoring scripts), the session ends after 12 hours. Every day someone has to repeat the browser sign-in, or the jobs silently lose access. The fallback is long-lived IAM access keys, which is the less secure choice this feature is meant to replace.

Proposed Solution

Any of these would help:

  • An account or administrator setting for maximum aws login session duration (for example up to 7 days), similar to IAM Identity Center session settings.
  • A refresh token that can be renewed non-interactively within an administrator-defined window.
  • Clear documented guidance for the "unattended host" case if aws login is not meant for it.

Other Information

No response

Acknowledgements

  • I may be able to implement this feature request
  • This feature might incur a breaking change

CLI version used

2.37.9

Environment details (OS name and version, etc.)

Ubuntu 24.04 (headless server), x86_64

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions