█▀█ █▀█ █▄▄ █ ▀█▀
█▄█ █▀▄ █▄█ █ █
orbit — Terminal UI for AWS
Browse, observe and manage your AWS resources from the terminal. Keyboard-driven, vim-style navigation. Built for operators who live in the shell.
Install
&&
The crate is named orbit-tui (the name orbit was taken on crates.io). The installed binary is orbit.
Pre-built binaries for macOS (arm64/x86_64), Linux (musl arm64/x86_64) and Windows (x86_64) are available on the releases page.
From source
Requires Rust 1.94+ and a C compiler.
&&
Quick start
Shell completions for bash, zsh and fish:
| # add to config.fish
Features
- 60+ resource types across 32 AWS services
- Keyboard-driven — vim keys,
:command mode,/filtering - Fuzzy filtering — client-side, or server-side AWS tag filters where supported
- Sortable columns — click a column header with
j/kto sort - Resource actions — start, stop, terminate EC2 instances, view secret values, SSM shell connect
- Data-driven — every resource type is a JSON definition, no hardcoded keys in Rust
- Multi-profile, multi-region — SSO, role assumption, console login, credential chain
- Demo mode —
--demostarts instantly with synthetic data for screenshots or testing - Read-only mode —
--readonlyblocks all mutating operations - Pagination — large resource lists with
]/[keys
Key bindings
| Key | Action |
|---|---|
j k ↑ ↓ |
Navigate items |
gg G |
Jump top / bottom |
PgUp PgDn Ctrl+b Ctrl+f |
Page up / down |
] [ |
Next / previous page |
Enter |
Describe resource or enter sub-resource |
d |
Describe selected resource |
: |
Open resource picker |
/ |
Filter (fuzzy match or AWS tag filters) |
J K |
Sort by column |
R |
Refresh |
0–5 |
Quick region switch |
? |
Help |
Ctrl+c |
Quit |
Esc Backspace |
Go back |
Resource-specific actions appear in the help screen (?). Examples: c connects to EC2 via SSM, x reveals a secret value, i lists ECR images.
Supported services
| Category | Service | Resources |
|---|---|---|
| Compute | EC2 | Instances, Volumes, Snapshots, AMIs |
| Lambda | Functions | |
| ECS | Clusters, Services, Tasks | |
| EKS | Clusters | |
| Auto Scaling | Auto Scaling Groups | |
| Storage | S3 | Buckets, Objects |
| Database | RDS | Instances, Snapshots |
| DynamoDB | Tables | |
| ElastiCache | Clusters | |
| Redshift | Clusters | |
| Networking | VPC | VPCs, Subnets, Security Groups, Network ACLs, Route Tables, Internet Gateways, NAT Gateways, Elastic IPs, Network Interfaces, VPC Endpoints, VPC Peering Connections |
| ELBv2 | Load Balancers, Listeners, Rules, Target Groups, Targets | |
| Route 53 | Hosted Zones, Records | |
| CloudFront | Distributions | |
| API Gateway | REST APIs | |
| Security | IAM | Users, Groups, Roles, Policies, Access Keys |
| Secrets Manager | Secrets | |
| KMS | Keys | |
| ACM | Certificates | |
| Cognito | User Pools | |
| WAFv2 | Web ACLs, IP Sets, Rule Groups | |
| Management | CloudFormation | Stacks, Stack Events, Stack Outputs |
| CloudWatch | Log Groups, Log Streams | |
| CloudTrail | Trails | |
| SSM | Parameters | |
| Messaging | SQS | Queues |
| SNS | Topics | |
| EventBridge | Event Buses, Rules | |
| Containers | ECR | Repositories, Images |
| DevOps | CodePipeline | Pipelines |
| CodeBuild | Projects | |
| Analytics | Athena | Workgroups |
| MSK | Clusters |
Missing a service? Open an issue.
Authentication
orbit uses the standard AWS credential chain: environment variables → SSO → console login → ~/.aws/credentials → ~/.aws/config → IMDSv2.
For SSO: if your profile uses Identity Center and the token is expired, orbit prompts you to authenticate. If you already logged in via aws sso login, the cached token is reused.
For role assumption: role_arn with source_profile or credential_source (EC2, ECS, Environment) is fully supported.
Set AWS_CA_BUNDLE if you are behind a corporate proxy with SSL inspection.
For LocalStack: orbit --endpoint-url http://localhost:4566.
Configuration
| Variable | Purpose |
|---|---|
AWS_PROFILE |
Default profile |
AWS_REGION |
Default region |
AWS_ENDPOINT_URL |
Custom endpoint (LocalStack) |
AWS_CA_BUNDLE |
Corporate SSL certificate bundle |
Logs: ~/Library/Application Support/orbit/orbit.log (macOS), ~/.config/orbit/orbit.log (Linux).
Contributing
Contributions welcome. See CONTRIBUTING.md. Before adding a new AWS service, please open an issue first.
Acknowledgments
Originally forked from taws by Hüseyin Babal. Built with Ratatui. Inspired by k9s.
License
Licensed under MIT. See LICENSE for details.
orbit is not affiliated with or endorsed by Amazon Web Services, Inc. "AWS" is a trademark of Amazon.com, Inc.