AWS CLI
awsOne command line interface for every Amazon Web Services API.
One command line interface for every Amazon Web Services API.
Otty extracts these into your secret store instead of syncing the files. Every generated manager config below leaves them out too.
credential_process, ca_bundle[default]region = us-east-1output = jsonca_bundle = /Users/octocat/certs/corp-root.pemmachine-local [profile work]region = eu-west-1output = tablecredential_process = /opt/homebrew/bin/aws-vault exec work --jsonmachine-local [profile sso]sso_start_url = https://example.awsapps.com/startOtty splits these out before upload and puts each machine’s own back on the way down — no templates to write. The lines above come from this tool’s test fixture in the catalog.
Not a subtraction from the paths above: this is everything else AWS CLI writes in your home directory that is state, not configuration. It keeps a whole-home manager like chezmoi from sweeping those up, and it still holds if the synced paths are ever widened.
credential_processca_bundle[default]region = us-east-1output = jsonca_bundle = /Users/octocat/certs/corp-root.pemmachine-local [profile work]region = eu-west-1output = tablecredential_process = /opt/homebrew/bin/aws-vault exec work --jsonmachine-local [profile sso]sso_start_url = https://example.awsapps.com/startEach machine keeps its own copy of these.
Only what the catalog names. A directory that syncs brings everything inside it except what is listed as excluded here.
Opens otty://sync/add/aws. Otty ships with this catalog, so the link only has to name the tool — nothing is downloaded.
Every one of these keeps the credential file out. None of them splits credential_process and ca_bundle for you — that part is Otty’s own sync, or a template you write by hand.