|
| 1 | +from typing import Any |
| 2 | + |
| 3 | +import boto3 |
| 4 | +import requests |
| 5 | + |
| 6 | +from aws_lambda_powertools.utilities import parameters |
| 7 | +from aws_lambda_powertools.utilities.typing import LambdaContext |
| 8 | + |
| 9 | +# assuming role from another account to get parameter there |
| 10 | +# see: https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html |
| 11 | +sts_client = boto3.client("sts") |
| 12 | +assumed_role_object = sts_client.assume_role( |
| 13 | + RoleArn="arn:aws:iam::account-of-role-to-assume:role/name-of-role", RoleSessionName="RoleAssume1" |
| 14 | +) |
| 15 | +credentials = assumed_role_object["Credentials"] |
| 16 | + |
| 17 | +# using temporary credentials in your SSMProvider provider |
| 18 | +# see: https://boto3.amazonaws.com/v1/documentation/api/latest/reference/core/session.html#module-boto3.session |
| 19 | +boto3_session = boto3.session.Session( |
| 20 | + region_name="us-east-1", |
| 21 | + aws_access_key_id=credentials["AccessKeyId"], |
| 22 | + aws_secret_access_key=credentials["SecretAccessKey"], |
| 23 | + aws_session_token=credentials["SessionToken"], |
| 24 | +) |
| 25 | +ssm_provider = parameters.SSMProvider(boto3_session=boto3_session) |
| 26 | + |
| 27 | + |
| 28 | +def lambda_handler(event: dict, context: LambdaContext): |
| 29 | + try: |
| 30 | + # Retrieve multiple parameters from a path prefix |
| 31 | + all_parameters: Any = ssm_provider.get_multiple("/lambda-powertools/") |
| 32 | + endpoint_comments = "https://jsonplaceholder.typicode.com/noexists/" |
| 33 | + |
| 34 | + for parameter, value in all_parameters.items(): |
| 35 | + |
| 36 | + if parameter == "endpoint_comments": |
| 37 | + endpoint_comments = value |
| 38 | + |
| 39 | + # the value of parameter is https://jsonplaceholder.typicode.com/comments/ |
| 40 | + comments: requests.Response = requests.get(endpoint_comments) |
| 41 | + |
| 42 | + return {"comments": comments.json()[:10]} |
| 43 | + except parameters.exceptions.GetParameterError as error: |
| 44 | + return {"comments": None, "message": str(error), "statusCode": 400} |
0 commit comments