Introducing atmos auth list: Visualize Your Authentication Configuration
We're excited to announce a powerful new command for managing authentication in Atmos: atmos auth list. This command provides comprehensive visibility into your authentication configuration, making it easier than ever to understand and manage complex authentication chains across multiple cloud providers and identities.
See it in action:
Why atmos auth list?
As cloud infrastructure grows more complex, so does authentication management. Modern teams often work with:
- Multiple cloud providers (AWS, Azure, GCP, Okta)
- Complex role assumption chains (SSO → base role → admin role → specific account)
- Multiple identities per environment (dev, staging, production)
- Team-specific access patterns (developer, operator, security auditor)
Without proper tooling, it becomes difficult to answer simple questions like:
- "What authentication providers do we have configured?"
- "Which identities can I use to access production?"
- "How does this identity authenticate? Through which provider?"
- "What's the complete authentication chain for this admin role?"
atmos auth list solves these challenges by providing clear, actionable visibility into your entire authentication configuration.
Key Features
🎨 Multiple Output Formats
Table Format (Default) Perfect for quick overviews with formatted tables showing key attributes:
atmos auth list
Tree Format Visualize hierarchical relationships and authentication chains:
atmos auth list --format tree
JSON/YAML Export Integrate with scripts and automation tools:
atmos auth list --format json | jq '.identities'
atmos auth list --format yaml > auth-config.yml
Graph Visualization Generate diagrams for documentation:
atmos auth list --format graphviz > auth-chain.dot
atmos auth list --format mermaid > auth-chain.mmd
atmos auth list --format markdown > docs/auth-config.md
🔍 Smart Filtering
Filter by providers or identities to focus on what matters:
# Show only AWS SSO providers
atmos auth list --providers=aws-sso
# View specific identities
atmos auth list --identities=admin,developer
# Show all providers (no identities)
atmos auth list --providers
🔗 Authentication Chain Visualization
Understand complex authentication flows at a glance. Chains show the complete path from provider to target identity:
aws-sso → base-role → admin-role → prod-account
This makes it immediately clear:
- Which provider authenticates you initially
- What roles you assume along the way
- The final identity you end up with
🎯 Real-World Examples
Quick Overview
$ atmos auth list
PROVIDERS
NAME KIND REGION START URL DEFAULT
aws-sso aws-sso us-east-1 https://example.awsapps.com/start ✓
okta okta https://example.okta.com
IDENTITIES
NAME KIND VIA PROVIDER VIA IDENTITY DEFAULT ALIAS
admin aws/assume-role aws-sso ✓ prod-admin
developer aws/assume-role aws-sso dev
ops aws/assume-role aws-sso admin ops-admin
Detailed Tree View
$ atmos auth list --format tree
Authentication Configuration
├─ aws-sso (aws-sso) [DEFAULT]
│ ├─ Region: us-east-1
│ ├─ Start URL: https://example.awsapps.com/start
│ └─ Identities
│ ├─ admin (aws/assume-role) [DEFAULT] [ALIAS: prod-admin]
│ │ ├─ Principal
│ │ │ └─ arn: arn:aws:iam::123456789012:role/AdminRole
│ │ └─ ops (aws/assume-role) [ALIAS: ops-admin]
│ │ └─ Principal
