1"use strict";(globalThis.webpackChunkwebsite=globalThis.webpackChunkwebsite||[]).push([[30089],{989626(e,n,i){i.r(n),i.d(n,{default:()=>d,metadata:()=>s});var s=i(231607),t=i(886070),c=i(845906);const r={slug:"describe-commands-identity-flag",title:"Identity Flag Support for Describe Commands",date:new Date("2025-11-03T12:00:00.000Z"),authors:["osterman"],tags:["feature"],release:"v1.197.0"},a={authorsImageUrls:[void 0]};function o(e){const n={a:"a",code:"code",h2:"h2",h3:"h3",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,c.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.a,{href:"/cli/commands/describe/usage",children:(0,t.jsx)(n.code,{children:"atmos describe"})})," family of commands now supports the ",(0,t.jsx)(n.a,{href:"/cli/commands/describe/component#flags",children:(0,t.jsx)(n.code,{children:"--identity"})})," flag, enabling runtime authentication when processing YAML template functions that access remote resources. This ensures that ",(0,t.jsx)(n.a,{href:"/functions/yaml/terraform.state",children:(0,t.jsx)(n.code,{children:"!terraform.state"})})," and ",(0,t.jsx)(n.a,{href:"/functions/yaml/terraform.output",children:(0,t.jsx)(n.code,{children:"!terraform.output"})})," functions work seamlessly without relying on ambient credentials."]}),"\n",(0,t.jsx)(n.h2,{id:"what-changed",children:"What Changed"}),"\n",(0,t.jsxs)(n.p,{children:["All ",(0,t.jsx)(n.code,{children:"atmos describe"})," subcommands now accept the ",(0,t.jsx)(n.code,{children:"--identity"})," flag for runtime authentication:"]}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/cli/commands/describe/stacks",children:(0,t.jsx)(n.code,{children:"atmos describe stacks --identity <name>"})})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/cli/commands/describe/component",children:(0,t.jsx)(n.code,{children:"atmos describe component <component> -s <stack> --identity <name>"})})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/cli/commands/describe/affected",children:(0,t.jsx)(n.code,{children:"atmos describe affected --identity <name>"})})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/cli/commands/describe/dependents",children:(0,t.jsx)(n.code,{children:"atmos describe dependents <component> -s <stack> --identity <name>"})})}),"\n"]}),"\n",(0,t.jsxs)(n.p,{children:["This brings feature parity with ",(0,t.jsx)(n.a,{href:"/cli/commands/terraform/usage",children:(0,t.jsx)(n.code,{children:"atmos terraform"})})," and ",(0,t.jsx)(n.a,{href:"/cli/commands/workflow",children:(0,t.jsx)(n.code,{children:"atmos workflow"})})," commands, which already support identity-based authentication."]}),"\n",(0,t.jsx)(n.h2,{id:"the-problem-we-solved",children:"The Problem We Solved"}),"\n",(0,t.jsxs)(n.p,{children:["By default, all ",(0,t.jsx)(n.code,{children:"atmos describe"})," commands execute YAML template functions (",(0,t.jsx)(n.code,{children:"!terraform.state"}),", ",(0,t.jsx)(n.code,{children:"!terraform.output"}),") and Go templates during stack processing. When these functions access remote Terraform state backends (S3, Azure Blob, GCS), they require authenticated cloud provider credentials."]}),"\n",(0,t.jsxs)(n.p,{children:[(0,t.jsx)(n.strong,{children:"Before this change"}),", users had to:"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["Manually run ",(0,t.jsx)(n.a,{href:"/cli/commands/auth/login",children:(0,t.jsx)(n.code,{children:"atmos auth login --identity <identity>"})})," before describe commands"]}),"\n",(0,t.jsxs)(n.li,{children:["Rely on ambient AWS credentials (environment variables, ",(0,t.jsx)(n.code,{children:"~/.aws/credentials"}),")"]}),"\n",(0,t.jsx)(n.li,{children:"Use EC2 instance profiles (not applicable for local development)"}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"The failure scenario looked like this:"})}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Stack configuration contains YAML function\n# components:\n# terraform:\n# app:\n# vars:\n# vpc_id: !terraform.output vpc.vpc_id\n\n# Command fails with timeout\n$ atmos describe component app -s prod\nError: context deadline exceeded (accessing S3 without credentials)\n"})}),"\n",(0,t.jsx)(n.h2,{id:"how-it-works",children:"How It Works"}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"--identity"})," flag is now available on all describe commands via the parent ",(0,t.jsx)(n.code,{children:"atmos describe"})," command. When specified, Atmos:"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Authenticates"})," using the specified identity before processing stacks"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Populates AuthContext"})," with cloud provider credentials"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Propagates credentials"})," to YAML function processors"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Executes template functions"})," with proper authentication"]}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:"The flag supports two modes:"}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"Explicit identity:"})}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"atmos describe stacks --identity my-aws-identity\n"})}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"Interactive selection:"})}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"atmos describe stacks --identity\n# Shows interactive selector to choose from configured identities\n"})}),"\n",(0,t.jsx)(n.h2,{id:"examples",children:"Examples"}),"\n",(0,t.jsx)(n.h3,{id:"basic-usage",children:"Basic Usage"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Describe stacks with specific identity\natmos de
1scribe stacks --identity my-aws-identity\n\n# Describe component with identity (shorthand)\natmos describe component vpc -s prod -i dev-admin\n\n# Describe affected components with authentication\natmos describe affected --ref main --identity prod-readonly\n\n# Describe dependents with identity\natmos describe dependents vpc -s prod --identity my-aws-identity\n"})}),"\n",(0,t.jsx)(n.h3,{id:"interactive-selection",children:"Interactive Selection"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Use --identity without a value for interactive selection\n$ atmos describe stacks --identity\n\n# Atmos shows selector:\n> dev-admin\n prod-readonly\n staging-deploy\n"})}),"\n",(0,t.jsx)(n.h3,{id:"combining-with-other-flags",children:"Combining with Other Flags"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Authenticate and filter results\natmos describe stacks --identity my-aws-identity --stack prod-use1 --format yaml\n\n# Authenticate and query specific values\natmos describe component vpc -s prod -i dev-admin --query .vars.cidr_block\n\n# Authenticate when describing affected components\natmos describe affected --identity prod-readonly --include-dependents --format json\n"})}),"\n",(0,t.jsx)(n.h2,{id:"disabling-yaml-functions",children:"Disabling YAML Functions"}),"\n",(0,t.jsxs)(n.p,{children:["If you want to see stack configurations ",(0,t.jsx)(n.strong,{children:"before"})," YAML functions are processed (without authentication), use the processing flags:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Disable YAML function processing\natmos describe stacks --process-functions=false\n\n# Disable Go template processing\natmos describe stacks --process-templates=false\n\n# Disable both\natmos describe stacks --process-functions=false --process-templates=false\n"})}),"\n",(0,t.jsx)(n.h2,{id:"use-cases",children:"Use Cases"}),"\n",(0,t.jsx)(n.h3,{id:"1-multi-account-development",children:"1. Multi-Account Development"}),"\n",(0,t.jsx)(n.p,{children:"When working across multiple AWS accounts, authenticate with the appropriate identity:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Development environment\natmos describe component app -s dev-use1 --identity dev-admin\n\n# Production environment (read-only)\natmos describe component app -s prod-use1 --identity prod-readonly\n"})}),"\n",(0,t.jsx)(n.h3,{id:"2-cicd-pipelines",children:"2. CI/CD Pipelines"}),"\n",(0,t.jsx)(n.p,{children:"Authenticate in CI/CD before describing affected components:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:'# In GitHub Actions, GitLab CI, etc.\natmos describe affected \\\n --identity "$ATMOS_IDENTITY" \\\n --ref "$BASE_BRANCH" \\\n --format json > affected.json\n'})}),"\n",(0,t.jsx)(n.h3,{id:"3-debugging-state-access",children:"3. Debugging State Access"}),"\n",(0,t.jsx)(n.p,{children:"When YAML functions access remote state, authenticate to avoid timeouts:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Component references outputs from another component\n# vars:\n# vpc_id: !terraform.output vpc.vpc_id\n\n# Describe with authentication\natmos describe component app -s prod --identity my-aws-identity\n"})}),"\n",(0,t.jsx)(n.h3,{id:"4-stack-introspection",children:"4. Stack Introspection"}),"\n",(0,t.jsx)(n.p,{children:"Describe entire stacks with authentication for complete configuration:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Get all stack configurations with resolved YAML functions\natmos describe stacks --identity my-aws-identity --format yaml > stacks.yaml\n"})}),"\n",(0,t.jsx)(n.h2,{id:"migration-guide",children:"Migration Guide"}),"\n",(0,t.jsxs)(n.p,{children:[(0,t.jsx)(n.strong,{children:"No migration required!"})," This is a backward-compatible enhancement:"]}),"\n",(0,t.jsxs)(n.p,{children:["\u2705 ",(0,t.jsx)(n.strong,{children:"Existing workflows continue to work:"})]}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["Commands without ",(0,t.jsx)(n.code,{children:"--identity"})," use ambient credentials (environment variables, AWS profiles)"]}),"\n",(0,t.jsx)(n.li,{children:"Default identity configuration is respected"}),"\n",(0,t.jsx)(n.li,{children:"CI/CD pipelines are unaffected"}),"\n"]}),"\n",(0,t.jsxs)(n.p,{children:["\u2705 ",(0,t.jsx)(n.strong,{children:"Opt-in when needed:"})]}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["Add ",(0,t.jsx)(n.code,{children:"--identity"})," flag when YAML functions require specific credentials"]}),"\n",(0,t.jsx)(n.li,{children:"Use interactive selection for convenience during local development"}),"\n",(0,t.jsx)(n.li,{children:"Specify explicit identities in automation scripts"}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"important-notes",children:"Important Notes"}),"\n",(0,t.jsx)(n.h3,{id:"default-behavior",children:"Default Behavior"}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsxs)(n.strong,{children:["By default, all ",(0,t.jsx)(n.code,{children:"atmos describe"})," commands execute:"]})}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["\u2705 YAML template functions (",(0,t.jsx)(n.code,{children:"!terraform.state"}),", ",(0,t.jsx)(n.code,{children:"!terraform.output"}),", etc.)"]}),"\n",(0,t.jsx)(n.li,{children:"\u2705 Go templates (Gomplate functions, Atmos functions)"}),"\n"]}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"To disable processing:"})}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["Use ",(0,t.jsx)(n.code,{children:"--process-functions=false"})," to skip YAML functions"]}),"\n",(0,t.jsxs)(n.li,{children:["Use ",(0,t.jsx)(n.code,{children:"--process-templates=false"})," to skip Go templates"]}),"\n"]}),"\n",(0,t.jsx)(n.h3,{id:"error-handling",children:"Error Handling"}),"\n",(0,t.jsx)(n.p,{children:(0,t.jsx)(n.strong,{children:"When authentication is not configured:"})}),"\n",(0,t.jsxs)(n.p,{children:["If your ",(0,t.jsx)(n.code,{children:"atmos.yaml"})," does not have an ",(0,t.jsx)(n.code,{children:"auth"})," section or has no identities configured, the behavior depends on whether you use the ",(0,t.jsx)(n.code,{children:"--identity"})," flag:"]}),"\n",(0,t.jsxs)(n.p,{children:["\u2705 ",(0,t.jsxs)(n.strong,{children:["Without ",(0,t.jsx)(n.code,{children:"--identity"})," flag"]})," - Commands work normally using ambient credentials (environment variables, AWS profiles, instance metadata)"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Works when auth not configured - uses ambient credentials\natmos de
1scribe stacks\n"})}),"\n",(0,t.jsxs)(n.p,{children:["\u274c ",(0,t.jsxs)(n.strong,{children:["With ",(0,t.jsx)(n.code,{children:"--identity"})," flag"]})," - Commands fail with a clear error message"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Fails when auth not configured but --identity provided\natmos describe stacks --identity my-identity\n# Error: authentication not configured in atmos.yaml\n# the --identity flag requires authentication to be configured in atmos.yaml with at least one identity\n"})}),"\n",(0,t.jsxs)(n.p,{children:["This prevents confusing authentication failures and guides you to configure the ",(0,t.jsx)(n.code,{children:"auth"})," section before using identity-based authentication."]}),"\n",(0,t.jsx)(n.h3,{id:"authentication-flow",children:"Authentication Flow"}),"\n",(0,t.jsxs)(n.p,{children:["When you specify ",(0,t.jsx)(n.code,{children:"--identity"}),":"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Identity lookup"})," - Atmos finds the identity configuration in ",(0,t.jsx)(n.code,{children:"atmos.yaml"})]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Authentication"})," - Authenticates using the provider's method (AWS SSO, OIDC, etc.)"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Credential storage"})," - Stores temporary credentials in XDG-compliant locations"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Context propagation"})," - Makes credentials available to YAML functions"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Stack processing"})," - Executes describe operations with authenticated access"]}),"\n"]}),"\n",(0,t.jsx)(n.h3,{id:"cicd-considerations",children:"CI/CD Considerations"}),"\n",(0,t.jsxs)(n.p,{children:[(0,t.jsx)(n.strong,{children:"For CI/CD pipelines"}),", we recommend:"]}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:["Set ",(0,t.jsx)(n.code,{children:"ATMOS_IDENTITY"})," environment variable instead of using ",(0,t.jsx)(n.code,{children:"--identity"})," flag"]}),"\n",(0,t.jsx)(n.li,{children:"Use explicit identity names (not interactive selection)"}),"\n",(0,t.jsx)(n.li,{children:"Ensure identity has appropriate permissions (read-only for describe operations)"}),"\n"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Good: CI/CD with explicit identity\nexport ATMOS_IDENTITY=ci-readonly\natmos describe affected --ref main\n\n# Better: Use flag for clarity\natmos describe affected --identity ci-readonly --ref main\n"})}),"\n",(0,t.jsx)(n.h2,{id:"technical-details",children:"Technical Details"}),"\n",(0,t.jsx)(n.h3,{id:"implementation",children:"Implementation"}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"--identity"})," flag is implemented as a ",(0,t.jsx)(n.strong,{children:"PersistentFlag"})," on the parent ",(0,t.jsx)(n.code,{children:"atmos describe"})," command, which means it automatically inherits to all subcommands:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# These are equivalent:\natmos describe stacks --identity my-aws-identity\natmos describe --identity my-aws-identity stacks\n"})}),"\n",(0,t.jsx)(n.h3,{id:"authmanager-propagation",children:"AuthManager Propagation"}),"\n",(0,t.jsxs)(n.p,{children:["When ",(0,t.jsx)(n.code,{children:"--identity"})," is specified:"]}),"\n",(0,t.jsxs)(n.ol,{children:["\n",(0,t.jsxs)(n.li,{children:["Command layer creates ",(0,t.jsx)(n.code,{children:"AuthManager"})," with identity configuration"]}),"\n",(0,t.jsxs)(n.li,{children:["Authenticates and populates ",(0,t.jsx)(n.code,{children:"AuthContext"})," with credentials"]}),"\n",(0,t.jsxs)(n.li,{children:["Passes ",(0,t.jsx)(n.code,{children:"AuthManager"})," to execution functions"]}),"\n",(0,t.jsxs)(n.li,{children:["Execution functions propagate ",(0,t.jsx)(n.code,{children:"AuthContext"})," to ",(0,t.jsx)(n.code,{children:"ConfigAndStacksInfo"})]}),"\n",(0,t.jsx)(n.li,{children:"YAML function processors access credentials from context"}),"\n"]}),"\n",(0,t.jsxs)(n.p,{children:["This ensures that ",(0,t.jsx)(n.code,{children:"!terraform.state"})," and ",(0,t.jsx)(n.code,{children:"!terraform.output"})," functions can access remote backends with proper authentication."]}),"\n",(0,t.jsx)(n.h3,{id:"performance",children:"Performance"}),"\n",(0,t.jsx)(n.p,{children:"Authentication adds minimal overhead:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"First run"}),": ~2-3 seconds for AWS SSO authentication (with browser)"]}),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Subsequent runs"}),": ",(0,t.jsx)(n.code,{children:"<100ms"})," (uses cached credentials)"]}
1),"\n",(0,t.jsxs)(n.li,{children:[(0,t.jsx)(n.strong,{children:"Credential refresh"}),": Automatic when credentials expire"]}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"related-documentation",children:"Related Documentation"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/cli/commands/auth/usage",children:"Authentication Overview"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsxs)(n.a,{href:"/cli/commands/describe/stacks",children:[(0,t.jsx)(n.code,{children:"atmos describe stacks"})," command"]})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsxs)(n.a,{href:"/cli/commands/describe/component",children:[(0,t.jsx)(n.code,{children:"atmos describe component"})," command"]})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsxs)(n.a,{href:"/cli/commands/describe/affected",children:[(0,t.jsx)(n.code,{children:"atmos describe affected"})," command"]})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsxs)(n.a,{href:"/cli/commands/describe/dependents",children:[(0,t.jsx)(n.code,{children:"atmos describe dependents"})," command"]})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/functions/yaml",children:"YAML Functions"})}),"\n"]}),"\n",(0,t.jsx)(n.h2,{id:"get-started",children:"Get Started"}),"\n",(0,t.jsx)(n.p,{children:"Try it out with your existing Atmos configuration:"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"# Interactive identity selection\natmos describe stacks --identity\n\n# Specific identity\natmos describe component <your-component> -s <your-stack> --identity <your-identity>\n\n# In CI/CD\natmos describe affected --identity $ATMOS_IDENTITY --ref main\n"})}),"\n",(0,t.jsxs)(n.p,{children:["Questions or feedback? Open an issue on ",(0,t.jsx)(n.a,{href:"https://github.com/cloudposse/atmos",children:"GitHub"})," or join our ",(0,t.jsx)(n.a,{href:"https://slack.cloudposse.com",children:"community Slack"}),"."]})]})}function d(e={}){const{wrapper:n}={...(0,c.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(o,{...e})}):o(e)}i.d(n,["assets",0,a,"contentTitle",0,undefined,"frontMatter",0,r,"toc",0,[{value:"What Changed",id:"what-changed",level:2},{value:"The Problem We Solved",id:"the-problem-we-solved",level:2},{value:"How It Works",id:"how-it-works",level:2},{value:"Examples",id:"examples",level:2},{value:"Basic Usage",id:"basic-usage",level:3},{value:"Interactive Selection",id:"interactive-selection",level:3},{value:"Combining with Other Flags",id:"combining-with-other-flags",level:3},{value:"Disabling YAML Functions",id:"disabling-yaml-functions",level:2},{value:"Use Cases",id:"use-cases",level:2},{value:"1. Multi-Account Development",id:"1-multi-account-development",level:3},{value:"2. CI/CD Pipelines",id:"2-cicd-pipelines",level:3},{value:"3. Debugging State Access",id:"3-debugging-state-access",level:3},{value:"4. Stack Introspection",id:"4-stack-introspection",level:3},{value:"Migration Guide",id:"migration-guide",level:2},{value:"Important Notes",id:"important-notes",level:2},{value:"Default Behavior",id:"default-behavior",level:3},{value:"Error Handling",id:"error-handling",level:3},{value:"Authentication Flow",id:"authentication-flow",level:3},{value:"CI/CD Considerations",id:"cicd-considerations",level:3},{value:"Technical Details",id:"technical-details",level:2},{value:"Implementation",id:"implementation",level:3},{value:"AuthManager Propagation",id:"authmanager-propagation",level:3},{value:"Performance",id:"performance",level:3},{value:"Related Documentation",id:"related-documentation",level:2},{value:"Get Started",id:"get-started",level:2}]])},845906(e,n,i){i.d(n,{R:()=>r,x:()=>a});var s=i(830758);const t={},c=s.createContext(t);function r(e){const n=s.useContext(c);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:r(e.components),s.createElement(c.Provider,{value:n},e.children)}},231607(e){e.exports=JSON.parse('{"permalink":"/changelog/describe-commands-identity-flag","editUrl":"https://github.com/cloudposse/atmos/edit/main/website/undefined/undefined","source":"@site/blog/2025-11-03-describe-commands-identity-flag.mdx","title":"Identity Flag Support for Describe Commands","description":"The atmos describe family of commands now supports the --identity flag, enabling runtime authentication when processing YAML template functions that access remote resources. This ensures that !terraform.state and !terraform.output functions work seamlessly without relying on ambient credentials.","date":"2025-11-03T12:00:00.000Z","tags":[{"inline":false,"label":"Feature","permalink":"/changelog/tags/feature","description":"New capabilities and functionality"}],"readingTime":6.19,"hasTruncateMarker":true,"authors":[{"name":"Erik Osterman","title":"Founder @ Cloud Posse","url":"https://github.com/osterman","imageURL":"https://github.com/osterman.png","key":"osterman","page":null}],"frontMatter":{"slug":"describe-commands-identity-flag","title":"Identity Flag Support for Describe Commands","date":"2025-11-03T12:00:00.000Z","authors":["osterman"],"tags":["feature"],"release":"v1.197.0"},"unlisted":false,"prevItem":{"title":"Zero-Configuration Terminal Output: Write O
1nce, Works Everywhere","permalink":"/changelog/zero-config-terminal-output"},"nextItem":{"title":"Critical Fix: Proper Shell Argument Quoting in Custom Commands","permalink":"/changelog/shell-argument-quoting-fix"}}')}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.