Rolle
Assume any role, any cloud. Open-source desktop app and CLI that hands short-lived AWS, Azure, and Google Cloud credentials to your tools and writes no secret to disk. Go + Wails v3 + React, signed self-updates, Homebrew cask.
Stack: Go, Wails, React, TypeScript, Tailwind v4, AWS, Azure, Google Cloud
Overview
Open-source desktop app and CLI for short-lived cloud credentials, built solo in Go with a Wails v3 + React desktop shell. Docs at getrolle.com.
- AWS: sign in to IAM Identity Center once and get every account and role you can reach. Chain
AssumeRolefrom any session. Add IAM users with optional MFA. Each active session is a profile backed bycredential_processfor the AWS CLI and SDKs. - Azure: sign in to an Entra ID tenant. Each subscription is a session that yields Resource Manager tokens.
- Google Cloud: reuse the credentials
gcloudalready has. Each project is a session. Impersonate service accounts. - Secrets live in the OS keychain. Short-lived credentials are owner-only files that expire. No telemetry.
- Imports what your machine already has: Identity Center portals from the AWS CLI and Granted, az CLI tenants, gcloud credentials, and a Leapp workspace.
- Desktop app: expiry countdowns, favorites, tags, one-click console and terminal, tray menu, signed self-updates. Ships as a Homebrew cask plus Windows and Linux builds.
