4 ms·
Related, I've been wondering if there's a tool that will generate a least-privilege policy out of an existing set of AWS CloudTrail records. It would be wonder
by bashinator 7y ago
Related, I've been wondering if there's a tool that will generate a least-privilege policy out of an existing set of AWS CloudTrail records. It would be wonderful if I could run terraform from an admin user, pull down the API calls, and build a policy from them.
- kmcquade 7y agoI hear you. Generating IAM policies based on CloudTrail records would be amazing. See my comment here: https://news.ycombinator.com/item?id=21262954#21264166 https://news.ycombinator.com/item?id=21262954#21264166 I hope to build this into our roadmap.
- thefrozenone 7y agoI believe trailscraper (https://github.com/flosell/trailscraper https://github.com/flosell/trailscraper) does this. See `trailscraper generate`.
- kmcquade 7y agoIt does, but some disclaimers: 1. The generated policies have Resources set to all, not to a specific resource ARN 2. It downloads all of the CloudTrail logs. This takes a while. Cloudtracker (https://github.com/duo-labs/cloudtracker https://github.com/duo-labs/cloudtracker) uses Amazon Athena, which is more efficient. In the future, I'd like to see a combined approach between all three of these tools to generate IAM policies based on Cloudtrail logs. 3. It is accurate to the point where there is a 1-to-1 mapping with the IAM actions vs CloudTrail logs. As I mentioned in other comments, since not every IAM Action is logged in CloudTrail and not every CloudTrail action matches IAM Actions, the results are not always accurate. With that being said, it is a wicked tool and you should try it out.
- bashinator 7y agoThank you! I'm glad to see there's progress on this. I've been holding off putting the infrastructure automation into CI/CD, due to the incredible amount of work it would take to create a least-access policy. Tooling like this will help a lot.