Sign inSign up

emptyset/cloudsweep

By emptyset

•Updated over 1 year ago

Cloud Sweep: Scan AWS resources, identify underutilized assets, optimize costs.

Image
Monitoring & observability
0

1.4K

emptyset/cloudsweep repository overview

⁠Cloud Sweep Docker Image Overview

The Cloud Sweep Docker image simplifies the process of running the AWS resource scanner without needing to install dependencies directly on your local machine. It encapsulates the full application within a Docker container for ease of use and portability.

You can access the source code for Cloud Sweep on GitHub: Cloudsweep GitHub Repository⁠.

⁠Key Features of the Docker Image

  • Pre-configured environment with all dependencies installed.
  • Easily run Cloud Sweep on any system with Docker installed.
  • Provides consistent execution across various environments.
  • Scalable and efficient resource scanning across AWS accounts and regions.

⁠Usage Instructions

⁠1. Pull the Docker Image

First, pull the latest version of the Cloud Sweep Docker image from Docker Hub:

docker pull emptyset/cloudsweep:latest
⁠2. Run the Docker Container

Use the following command to run the Docker container and execute Cloud Sweep:

docker run --rm \
  -e AWS_ACCESS_KEY_ID=<your-access-key-id> \
  -e AWS_SECRET_ACCESS_KEY=<your-secret-access-key> \
  -v $(pwd)/output:/app/output \
  emptyset/cloudsweep:latest \
  --organization-role <organization_role> \
  --runner-role <runner_role> \
⁠Explanation of Flags:
usage: main.py [-h] [--organization-role ORGANIZATION_ROLE] [--runner-role RUNNER_ROLE] [--list-scanners] [--list-accounts]
               [--accounts ACCOUNTS] [--scanners SCANNERS] [--regions REGIONS] [--max-workers MAX_WORKERS] [--days-threshold DAYS_THRESHOLD]
               [--upload-confluence]

AWS Scanner CLI

options:
  -h, --help            show this help message and exit
  --organization-role ORGANIZATION_ROLE
                        IAM Role Name for querying the organization.
  --runner-role RUNNER_ROLE
                        IAM Role Name for scanning organization accounts.
  --list-scanners       List all available scanners.
  --list-accounts       List all accounts in the AWS Organization.
  --accounts ACCOUNTS   Comma-separated list of account IDs or 'all' for all accounts.
  --scanners SCANNERS   Comma-separated list of scanners or 'all' to use all scanners.
  --regions REGIONS     Comma-separated list of regions or 'all' to use all regions.
  --max-workers MAX_WORKERS
                        Maximum number of workers to use (default: one less than the number of CPUs).
  --days-threshold DAYS_THRESHOLD
                        The number of days to look back at resource metrics and history to determine if something is unused (default: 90
                        days).
  --upload-confluence   Set to True if you want to upload reports to Confluence.
  • --rm: Automatically removes the container after it exits.
  • -e AWS_ACCESS_KEY_ID: Passes your AWS access key ID as an environment variable.
  • -e AWS_SECRET_ACCESS_KEY: Passes your AWS secret access key as an environment variable.
  • -v $(pwd)/output:/app/output: Maps the local output directory to the container's /app/output directory for saving scan results.
  • emptyset/cloudsweep:latest: The Docker image to use.
  • Cloud Sweep arguments (--organization-role, --runner-role): Specify the IAM roles and scanning options.
⁠3. Customizing Scans

Customize your scan by providing additional command-line arguments:

  • Specify Regions:

    --regions us-west-1,us-east-1
    
  • Run Specific Scanners:

    --scanners ec2,iam
    
  • Set Maximum Workers:

    --max-workers 4
    

### 4. View Reports

After the scan is complete, the results will be saved in the `output` directory on your local machine. Open the generated HTML report to view detailed insights about unused resources.

⁠Example Commands

⁠Scan All Regions Using All Scanners
docker run --rm \
  -e AWS_ACCESS_KEY_ID=<your-access-key-id> \
  -e AWS_SECRET_ACCESS_KEY=<your-secret-access-key> \
  -v $(pwd)/output:/app/output \
  emptyset/cloudsweep:latest \

Tag summary

Content type

Image

Digest

sha256:cec22adcb…

Size

16.1 MB

Last updated

over 1 year ago

docker pull emptyset/cloudsweep