/** * Who chant would act as in AWS — the lexicon half of `chant lifecycle whoami` * (chant #1982). * * `sts:GetCallerIdentity` on the same transport every read uses, so the answer * cannot describe a target the read does not reach: the endpoint override, the * region and the signing decision are resolved by `read-client.ts` once, for * both. That parity is the point of the command — a whoami that reports real * AWS while `describeResources` reads Floci is worse than none — and a test * pins it. * * ## What the region actually is * * The native read transport takes its region from the stack being observed * (`stacks[].region`, #1261) and falls back to `us-east-1` inside `serviceUrl`. * It does NOT read `AWS_REGION`. So that is what is reported, including the * awkward case: an operator whose shell exports `AWS_REGION=eu-west-1` and * whose project declares no stack region is reading us-east-1, and has had no * way to find that out short of a wrong answer. `source` names it. * * ## Credentials * * `resolveCredentials` (./api/sigv4.ts) reads `AWS_ACCESS_KEY_ID` / * `AWS_SECRET_ACCESS_KEY` and nothing else — no profile file, no IMDS, no * container endpoint, deliberately. `AWS_PROFILE` alone therefore signs * nothing, and against real AWS the call comes back unauthorized. That is * reported as `no-credentials` naming the profile, which is a far better * answer than an empty stack read an hour later. * * No credential value is ever returned. The identity is the principal ARN the * service itself answers with, and the scope is an account and a region. */ import type { DescribeIdentityOptions, DescribeIdentityResult } from "@intentius/chant/lexicon"; import { type AwsReadClientOptions } from "./api/read-client.js"; /** Options this module needs beyond the contract — the injectable transport, for tests. */ export interface CallerIdentityOptions extends DescribeIdentityOptions { client?: AwsReadClientOptions; } /** * The AWS `describeIdentity`. Returns the STS principal and the account+region * scope, or a typed refusal — never a guessed identity and never an empty one. */ export declare function describeIdentity(options: CallerIdentityOptions): Promise; //# sourceMappingURL=caller-identity.d.ts.map