{"repo":"JamesWoolfenden/pike","free":true,"listed":false,"github":"https://github.com/JamesWoolfenden/pike","clone":"git clone https://github.com/JamesWoolfenden/pike.git","description":"Pike is a tool for determining the permissions or policy required for IAC code","language":"HCL","stars":927,"topics":["iac","policy","terraform","bridgecrew","security","aws","gcp"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Pike Pike is a tool to determine the minimum IAM permissions required to run OpenTofu/Terraform infrastructure code. What's new? - JSON modules support. - GCP compare, checks IAC permissions required versus a deployed role. - Backend detection S3 and GCP. Pike currently supports OpenTofu/Terraform and supports multiple providers (AWS, GCP and AZURE); Azure is the newest with AWS having the most supported resources . Feel free to submit PR or Issue if you find an issue or even better add new resources, and then I'll take a look at merging it ASAP. Note on Placeholder Resources: Some resources in the lookup maps (particularly GCP organization, folder, and billing-level resources) are marked with placeholder entries. These resources are recognized by Pike but do not have empirically validated IAM permissions because they require organization-level access or specialized account types that are difficult to test. When Pike encounters these resources, it will not error, but the permissions have not been validated through actual resource lifecycle testing. CAVEAT The outputs of this tool are your first step, if you have AWS, you can now generate resources partially, there are no conditions and even partial resources are wild-carded (for now). (for AWS)minimum best practice would go further (and I am working on it as well), you will need to modify these permissions to the required in your environment by adding these restrictions, you can also deploy using short-lived credentials (usin","default_branch":null,"files":null,"tree":[],"storefront":"/r/JamesWoolfenden","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/JamesWoolfenden/pike/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}