{"repo":"bridgecrewio/AirIAM","free":true,"listed":false,"github":"https://github.com/bridgecrewio/AirIAM","clone":"git clone https://github.com/bridgecrewio/AirIAM.git","description":"Least privilege AWS IAM Terraformer","language":"Python","stars":825,"topics":["bridgecrew","iam","privileges-model","aws","terraform","aws-iam","aws-security","aws-security-automation","hacktoberfest"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"AirIAM is an AWS IAM to least privilege Terraform execution framework. It compiles AWS IAM usage and leverages that data to create a least-privilege IAM Terraform that replaces the exiting IAM management method. AirIAM was created to promote immutable and version-controlled IAM management to replace today's manual and error prone methods. Table of contents - Table of contents - Introduction - Features - Commands - Usage - Data Flow - Examples - Getting Started - Installation - Using Pip - Using brew (MacOS Only) - Recommended flow - FAQ - Alternatives - AWS IAM Cleanup Tools - AWS IAM Policy Management Tools - Migration of AWS to Terraform Tools - Contributing - Support Introduction AirIAM scans existing IAM usage patterns and provides a simple method to migrate IAM configurations into a right-sized Terraform plan. It identifies unused users, roles, groups, policies and policy attachments and replaces them with a Least Privileges Terraform code modelled to manage AWS IAM. By moving all IAM configurations into Terraform code, admins can start tracking, auditing and modifying IAM configurations as part of their standard infrastructure-as-code development provisioning processes. AirIAM is battle-tested and is recommended for use in Dev, QA and test environments that have been previously managed by humans. It is design to result in minimal impact on existing workloads. If you are interested in migrating a Prod account, contact us at info@bridgecrew.io for some helpful tips. Featu","default_branch":null,"files":null,"tree":[],"storefront":"/r/bridgecrewio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bridgecrewio/AirIAM/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}