seclogin — a tray app that opens SSM port-forward tunnels to private AWS resources (no VPN, no bastion). Installers are published here; the source is private.
brew install --cask craftyshelf/tap/secloginUpgrade later with brew upgrade --cask seclogin. The build is unsigned; the
cask strips the quarantine flag so it opens without the Gatekeeper prompt.
sudo apt update
curl -L https://github.com/craftyshelf/homebrew-tap/releases/latest/download/seclogin_amd64.deb -o seclogin.deb
sudo apt install ./seclogin.debUpgrade by re-running the same commands. (Needs libwebkit2gtk-4.1-0 and
libayatana-appindicator3-1, which apt install ./… pulls in automatically.)
sudo dnf install https://github.com/craftyshelf/homebrew-tap/releases/latest/download/seclogin_x86_64.rpmdnf installs straight from the URL and pulls in webkit2gtk4.1 automatically.
Upgrade by re-running the same command.
The app writes a starter config to ~/.seclogin/ on first launch (same on
macOS and Linux). Fill in your [sso] block, then click Connect to AWS.