Cloud Sweep: Scan AWS resources, identify underutilized assets, optimize costs.
1.4K
The Cloud Sweep Docker image simplifies the process of running the AWS resource scanner without needing to install dependencies directly on your local machine. It encapsulates the full application within a Docker container for ease of use and portability.
You can access the source code for Cloud Sweep on GitHub: Cloudsweep GitHub Repository.
First, pull the latest version of the Cloud Sweep Docker image from Docker Hub:
docker pull emptyset/cloudsweep:latest
Use the following command to run the Docker container and execute Cloud Sweep:
docker run --rm \
-e AWS_ACCESS_KEY_ID=<your-access-key-id> \
-e AWS_SECRET_ACCESS_KEY=<your-secret-access-key> \
-v $(pwd)/output:/app/output \
emptyset/cloudsweep:latest \
--organization-role <organization_role> \
--runner-role <runner_role> \
usage: main.py [-h] [--organization-role ORGANIZATION_ROLE] [--runner-role RUNNER_ROLE] [--list-scanners] [--list-accounts]
[--accounts ACCOUNTS] [--scanners SCANNERS] [--regions REGIONS] [--max-workers MAX_WORKERS] [--days-threshold DAYS_THRESHOLD]
[--upload-confluence]
AWS Scanner CLI
options:
-h, --help show this help message and exit
--organization-role ORGANIZATION_ROLE
IAM Role Name for querying the organization.
--runner-role RUNNER_ROLE
IAM Role Name for scanning organization accounts.
--list-scanners List all available scanners.
--list-accounts List all accounts in the AWS Organization.
--accounts ACCOUNTS Comma-separated list of account IDs or 'all' for all accounts.
--scanners SCANNERS Comma-separated list of scanners or 'all' to use all scanners.
--regions REGIONS Comma-separated list of regions or 'all' to use all regions.
--max-workers MAX_WORKERS
Maximum number of workers to use (default: one less than the number of CPUs).
--days-threshold DAYS_THRESHOLD
The number of days to look back at resource metrics and history to determine if something is unused (default: 90
days).
--upload-confluence Set to True if you want to upload reports to Confluence.
--rm: Automatically removes the container after it exits.-e AWS_ACCESS_KEY_ID: Passes your AWS access key ID as an environment variable.-e AWS_SECRET_ACCESS_KEY: Passes your AWS secret access key as an environment variable.-v $(pwd)/output:/app/output: Maps the local output directory to the container's /app/output directory for saving scan results.emptyset/cloudsweep:latest: The Docker image to use.--organization-role, --runner-role): Specify the IAM roles and scanning options.Customize your scan by providing additional command-line arguments:
Specify Regions:
--regions us-west-1,us-east-1
Run Specific Scanners:
--scanners ec2,iam
Set Maximum Workers:
--max-workers 4
### 4. View Reports
After the scan is complete, the results will be saved in the `output` directory on your local machine. Open the generated HTML report to view detailed insights about unused resources.
docker run --rm \
-e AWS_ACCESS_KEY_ID=<your-access-key-id> \
-e AWS_SECRET_ACCESS_KEY=<your-secret-access-key> \
-v $(pwd)/output:/app/output \
emptyset/cloudsweep:latest \
Content type
Image
Digest
sha256:cec22adcb…
Size
16.1 MB
Last updated
over 1 year ago
docker pull emptyset/cloudsweep