Thanks for chiming in, I have made some progress and got it working to an extent. Reasons for confusion:
- how
STS.assume_roleworks, I believe a name likefetch_role_credentialswould be more apt, since as far as I can tell it is fully up to developers to use/cache/refresh/propagate these temporary credentials.assume_rolesuggests some stateful (shudder) change that applies to subsequent requests. I stumbled on this and found it very helpful, maybe link to it from the README? - differences between the release and master for
ex_aws_sts, there is aawscli_auth_adapter: ExAws.STS.AuthCache.AssumeRoleCredentialsProviderin master and READMIE that is not in the 2.0 release. - incompatibility with tools like
stavro/arc, which rely solely on the fixed, hard coded credentials from aws_ex config, so I don’t think IAM roles can be used with those tools (I have created an issue forarc) - diabolically opaque error messages from Amazon
Again, thanks for your input, any further help is equally appreciated.


















