aws-config

Resolves AWS credentials and shared configuration for every AWS SDK for Rust client.

SDK
Cargo
v1.12.0
686 stars
Apache License 2.0

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
93 /100 Excellent
Development Activity 100
Maintenance 100
Community 84
Maturity 60
Momentum 28

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
77 /100 Good
Architecture 84
Code Quality 86
Innovation 74
Learning Curve 65

aws-config is the credential and configuration resolution crate underlying the AWS SDK for Rust. It implements the AWS shared config/credentials file format, environment-variable overrides, IMDS (EC2 instance metadata) and ECS container credential providers, SSO and web-identity-token (IRSA/OIDC) authentication, and the AWS STS AssumeRole flow, exposing them all behind a single aws_config::load_from_env()/defaults() entry point that every generated AWS service client (S3, DynamoDB, Lambda, etc.) consumes to construct its SdkConfig.

The crate lives inside the smithy-lang/smithy-rs monorepo, which houses the Smithy code generators that produce the entire AWS SDK for Rust as well as its hand-written runtime crates (aws-config, aws-credential-types, aws-types, and others). Because virtually every Rust application calling AWS APIs depends on aws-config transitively to establish credentials and region/endpoint configuration, it is one of the most widely used crates in the Rust AWS ecosystem despite being maintained as part of the SDK’s code-generation tooling rather than a standalone client library.

What You Get

  • A default credential provider chain implementing AWS’s standard resolution order (env vars, profile, IMDS, ECS, SSO, web identity)
  • Shared config/credentials file parsing (~/.aws/config, ~/.aws/credentials) with profile support
  • SSO (AWS IAM Identity Center) login-based credential resolution
  • Web identity token (IRSA/OIDC, e.g. EKS service accounts) and STS AssumeRole support
  • IMDS (EC2 instance metadata) and ECS container credential providers
  • Behavior-version and retry/timeout configuration shared across all generated AWS service clients

Common Use Cases

  • Bootstrapping any AWS SDK for Rust service client (S3, DynamoDB, Lambda, etc.) with resolved credentials and region
  • Running Rust services on EKS that authenticate via IRSA (IAM Roles for Service Accounts) web identity tokens
  • Local development workflows using AWS SSO / IAM Identity Center login instead of static keys
  • Cross-account access via STS AssumeRole from a Rust application or Lambda function
  • Reading standard AWS CLI-style profile configuration from ~/.aws/config in Rust tooling

Under The Hood

Architecture - aws-config lives at aws/rust-runtime/aws-config inside the smithy-lang/smithy-rs monorepo, which also houses the Kotlin/Gradle-based Smithy code generators (codegen-core, codegen-client) that produce the rest of the AWS SDK for Rust. Its src/ is organized around one submodule per credential source — imds/, sso/, sts/, profile/, environment/, login/, default_provider/ — each implementing a provider that can be composed into the overall resolution chain, with provider_config.rs and default_provider.rs orchestrating the standard AWS credential-lookup order across all of them.

Tech Stack - Rust (edition 2021, rust-version 1.94.1 per Cargo.toml), depending on sibling aws-smithy-* runtime crates (aws-smithy-async, aws-smithy-runtime, aws-smithy-runtime-api) plus aws-sdk-sso/aws-sdk-ssooidc for the SSO flow, gated behind Cargo features (rt-tokio, sso, credentials-process, credentials-login) so consumers only compile the auth paths they use. The monorepo build itself uses Gradle (JDK 17) to drive the Smithy code generators, separate from the plain cargo build of the runtime crates.

Code Quality - The crate ships test-data/ and integration-tests/ directories (explicitly excluded from the published crate via Cargo.toml’s exclude), and the broader smithy-rs repo runs cargoCheck/cargoTest/cargoClippy through Gradle tasks as part of CI. Maintained directly by the ‘AWS Rust SDK Team’ (per Cargo.toml authors), with the monorepo showing very active, consistent commit activity per its GitHub health metrics.

API Design - The primary entry point is a single async call — aws_config::load_defaults(BehaviorVersion::latest()).await — that returns an SdkConfig consumed by every generated service client’s Client::new(&config) constructor, hiding the credential-chain complexity behind one function while still allowing fine-grained overrides (explicit profile name, custom credential provider, explicit region) for advanced cases. This ‘one function, sensible defaults, escape hatches available’ pattern is consistent across the whole AWS SDK for Rust, since every service crate expects the same SdkConfig shape from aws-config.

Used by 36 apps in this directory

Rust
79%
Apache 2.0

TensorZero

Ab Testing Experimentation · AI Development · Monitoring

11,717

TensorZero unifies the LLM gateway, observability, evaluation, optimization, and experimentation stack behind a single OpenAI-compatible API, built in Rust for sub-millisecond p99 latency.

View details
53
Repo Health
87
Technical
69
Dependency
Built with
Rust 79%
TypeScript 15%
Updated 4 months ago
Rust
79%
Apache 2.0

TensorZero

Ab Testing Experimentation · AI Development · Monitoring

11,717

TensorZero unifies the LLM gateway, observability, evaluation, optimization, and experimentation stack behind a single OpenAI-compatible API, built in Rust for sub-millisecond p99 latency.

View details
53
Repo Health
87
Technical
69
Dependency
Built with
Rust 79%
TypeScript 15%
Updated 4 months ago
Rust
79%
Apache 2.0

TensorZero

Ab Testing Experimentation · AI Development · Monitoring

11,717

TensorZero unifies the LLM gateway, observability, evaluation, optimization, and experimentation stack behind a single OpenAI-compatible API, built in Rust for sub-millisecond p99 latency.

View details
53
Repo Health
87
Technical
69
Dependency
Built with
Rust 79%
TypeScript 15%
Updated 4 months ago
Rust
79%
Apache 2.0

TensorZero

Ab Testing Experimentation · AI Development · Monitoring

11,717

TensorZero unifies the LLM gateway, observability, evaluation, optimization, and experimentation stack behind a single OpenAI-compatible API, built in Rust for sub-millisecond p99 latency.

View details
53
Repo Health
87
Technical
69
Dependency
Built with
Rust 79%
TypeScript 15%
Updated 4 months ago
Rust
83%
AGPL 3.0

Vaultwarden

Password Manager · Security

68,240

Unofficial Bitwarden-compatible server in Rust — run the full Bitwarden ecosystem on a Raspberry Pi using every official client you already have, without the multi-container overhead.

View details
89
Repo Health
69
Technical
70
Dependency
Built with
Rust 83%
Updated 2 weeks ago
Rust
83%
AGPL 3.0

Vaultwarden

Password Manager · Security

68,240

Unofficial Bitwarden-compatible server in Rust — run the full Bitwarden ecosystem on a Raspberry Pi using every official client you already have, without the multi-container overhead.

View details
89
Repo Health
69
Technical
70
Dependency
Built with
Rust 83%
Updated 2 weeks ago
Rust
83%
AGPL 3.0

Vaultwarden

Password Manager · Security

68,240

Unofficial Bitwarden-compatible server in Rust — run the full Bitwarden ecosystem on a Raspberry Pi using every official client you already have, without the multi-container overhead.

View details
89
Repo Health
69
Technical
70
Dependency
Built with
Rust 83%
Updated 2 weeks ago
Rust
50%
Apache 2.0

Vibe Kanban

AI Agents · AI Code Assistants · Project Management

28,209

A kanban board for planning work and dispatching Claude Code, Codex, Gemini CLI, and eight other coding agents into isolated git worktrees, then reviewing and merging their diffs from one UI.

View details
75
Repo Health
75
Technical
64
Dependency
Built with
Rust 50%
TypeScript 46%
Updated 2 weeks ago
Rust
98%
Other

Zed

Code Editors · Collaboration · Developer Tools

90,979

High-performance, multiplayer code editor built in Rust by the creators of Atom and Tree-sitter, with native AI integration and real-time collaboration.

View details
94
Repo Health
88
Technical
72
Dependency
Built with
Rust 98%
Updated 1 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers