Resource → Cloud & Kubernetes Shell
For cloud accounts (AWS, Azure) and Kubernetes clusters, the Connect terminal icon in the location tree opens a command-line session pre-authenticated against the resource — the worker signs in on your behalf using the credentials supplied for the connection. Each resource kind gets its own dedicated CLI session:
- AWS Shell — run
awsCLI commands against the region you pick at connect time. - Azure Shell — run
azCLI commands against the subscription configured on the resource. - Kubernetes shell — run
kubectlcommands (the shorthandkworks too) against the cluster context configured on the resource.
These are focused command lines, not general-purpose shells: only the resource’s own CLI is accepted, plus a small set of safe output filters you can pipe into (grep, head, tail, sort, uniq, cut, wc, tr, column, jq). Arbitrary shell commands are rejected. The CLIs also cannot be extended or reconfigured from inside the session: Azure extensions cannot be installed, and on AWS and Kubernetes the CLI’s own configuration is read-only, so aws configure set and kubectl config set-* are refused. Pass options such as --region or --output on the command instead.
The terminal experience otherwise mirrors the SSH terminal (see SSH) — only the pre-connect step differs. Database resources open a SQL shell instead (Database Shell), Windows resources open a graphical Remote Desktop (RDP), hosts reachable over VNC open a VNC desktop, and web applications open a browser-based Web Application session.
Each connection opens its own pin. You can open up to three shell sessions per user/resource by default, across all shell modes; administrators can change this limit. Select an existing connection pin to return to it without opening another shell. This limit is shared with native SSH connections.
What you can do
- Run CLI commands after MisterShell authenticates the connection.
- On AWS resources, pick the region to work in before connecting.
- Enable AI assistance and session sharing just like on SSH sessions.
Common tasks
Start a session
- AWS: pick the region in the connection-options dialog after clicking the Connect terminal icon in the location tree. The list offers the regions configured on the resource. Azure / Kubernetes: there is nothing to pick — the subscription or cluster context is part of the resource’s connection settings.
- Click Connect. The shell opens once the cloud provider confirms authentication.
If Authentication required appears, enter credentials or choose a compatible personal/team credential with Use vault, then click Connect. Saved credentials for templates are used automatically. See providing credentials when connecting.
Switch region (AWS)
- Click Connect beside the resource in the location tree.
- Pick the other region and click Connect in the dialog.
The new shell opens in its own pin. Disconnect an existing shell first if you have reached the resource limit.
To work against a different Azure subscription or Kubernetes cluster context, edit the resource’s connection settings (or create one resource per subscription / context) — these are fixed per resource, not chosen at connect time.
Share and AI-assist
Identical to an SSH session. See Resource → SSH Terminal for the detailed workflow.
Conditions and blockers
- You do not have permission to open sessions — you lack the
app.resources.executepermission. - A warning that the region list is not available for this resource (AWS) — the resource has no configured regions; edit the resource and configure at least one region before connecting.
- Authentication required — enter credentials or choose a compatible personal/team entry with Use vault. To avoid the prompt for future connections, save your credential for the template in Account → Personal Vault.
Permissions
- Open an interactive session:
app.resources.execute. - Share a session and invite participants:
app.session.execute. - Attach AI assistance:
app.ai.executeand a configured Session Assist agent with an available model.