aws-leastprivilege
aws-cloudformation-templates
Our great sponsors
aws-leastprivilege | aws-cloudformation-templates | |
---|---|---|
5 | 3 | |
109 | 33 | |
- | - | |
3.4 | 4.4 | |
8 months ago | 12 days ago | |
Python | Python | |
MIT License | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
aws-leastprivilege
- “IAM Access Analyzer” for a Cloudformation Stack’s Service Role?
-
Can you build an IAM list of Actions based on running infrastructure and/or cloud formation template?
From a template, this is the closest I've gotten: https://github.com/iann0036/aws-leastprivilege , and also check out iamlive (thanks /u/rowanu!) if you can insert the recorder between the application and the AWS endpoints.
-
IAM Least Privilege for IAM for SAM/CloudFormation?
Check out https://github.com/iann0036/aws-leastprivilege, though note that it doesn't currently support SAM, so you might want to create a change set and grab the transformed template to use.
-
Permissions - is there an easy way?
I've personally attempted to fix this before with https://github.com/iann0036/aws-leastprivilege, which uses mappings with permissions (based on some incremental permissions testing), but also defaults down to examining the permission schemes publicly available in some (but not all) resource types. More info in the README.
- CloudFormation Stack Permissions
aws-cloudformation-templates
-
Fortigate HA in AWS
There's some extra documentation on their github as well as a cloudformation template you can deploy from.
- AWS LB Deployment
-
VIPs, EIPs, AWS, and failover failures..
I'm deploying a couple of FortiGate VMs in AWS. I've fiddled with the Cloudformation templates from the Fortinet Github repository, and got everything working, in as much as it runs and fails over across two AZs. It's the design from https://github.com/fortinet/aws-cloudformation-templates/tree/main/FGCP/6.4/DualAZ
What are some alternatives?
iamlive - Generate an IAM policy from AWS, Azure, or Google Cloud (GCP) calls using client-side monitoring (CSM) or embedded proxy
sceptre - Build better AWS infrastructure
PMapper - A tool for quickly evaluating IAM permissions in AWS.
aws-sso-util - Smooth out the rough edges of AWS SSO (temporarily, until AWS makes it better).
policy_sentry - IAM Least Privilege Policy Generator
awesome-aws - A curated list of awesome Amazon Web Services (AWS) libraries, open source repos, guides, blogs, and other resources. Featuring the Fiery Meter of AWSome.
trailscraper - A command-line tool to get valuable information out of AWS CloudTrail
sniftran - Fortinet packet sniffer convertor
cfn-leaprog - cfn-LEAst-Privilege-ROle-Generator: Experimental tool for generating least privileged IAM roles for CloudFormation and Service Catalog Launch Constraints.