Audit IAM users and access keys across AWS Organizations — interactive HTML dashboard included
1.8K
Audits IAM users and access keys across all accounts in an AWS Organization. Generates an interactive HTML dashboard — available locally at localhost:8000 or delivered via Slack with a presigned S3 URL when running on AWS Fargate.
| Mode | How | Output |
|---|---|---|
| Local | Docker + AWS profile | Dashboard at localhost:8000 |
| Fargate | EventBridge Scheduler (every Monday 9am) | Slack notification with presigned URL (48hs) |
~/.aws)AWSControlTowerExecution)docker run --rm \
-v ~/.aws:/root/.aws \
-v $(pwd)/output:/app/output \
-p 8000:8000 \
gerardokaztro/iam-audit \
--profile YOUR-AWS-PROFILE \
--role YOUR-AUDIT-ROLE
When the scan finishes, open your browser at:
http://localhost:8000
Press Ctrl+C to stop the server.
Deploy the infrastructure with Terraform — the task runs automatically every Monday at 9am (Lima, UTC-5) and sends a Slack notification with the dashboard URL.
AWSControlTowerExecution)cd infra
cp backend.hcl.example backend.hcl
cp terraform.tfvars.example terraform.tfvars
# Edit both files with your values
terraform init -backend-config=backend.hcl
terraform plan
terraform apply
All files are saved to ./output/ locally or to s3://iam-audit-reports-{account_id}/reports/YYYY-MM-DD/ on Fargate:
| File | Content |
|---|---|
iam_audit_report_TIMESTAMP.html | Interactive dashboard |
iam_audit_report_TIMESTAMP.csv | IAM findings |
root_audit_report_TIMESTAMP.csv | Root account findings |
cloudtrail_events_TIMESTAMP.csv | Remediation tracking |
| Parameter | Required | Description |
|---|---|---|
--profile | No (local only) | AWS CLI profile name |
--role | No | Role name to assume in each account (default: AWSControlTowerExecution) |
Deployed via Terraform in your Security account:
| Resource | Purpose |
|---|---|
| ECS Fargate Task | Runs the audit container |
| EventBridge Scheduler | Triggers every Monday 9am Lima |
| S3 Bucket | Stores reports (90-day lifecycle) |
| Secrets Manager | Stores Slack webhook URL |
| IAM Roles | Task Role + Execution Role |
All releases are built for linux/amd64 from a pinned base image digest.
Recommended usage by digest for reproducibility:
docker pull gerardokaztro/iam-audit@sha256:2876b73349c6a8c4847d4478a8e1f65971a6e1a3978320a2817e0ee3426e4ea4
Content type
Image
Digest
sha256:6b416a9dc…
Size
77.8 MB
Last updated
6 months ago
docker pull gerardokaztro/iam-audit