duo-labs / duo-labs/cloudmapper
iam_report identifies unused incorrectly
- Dominant language
- JavaScript
- Stars
- 6.3k
- Forks
- 836
- PR merge metrics
- No merged PRs in 30d
Description
Hey!
I've been using the iam_report, and it's really handy for me. I tried to rightsize my IAM according to the report, and found 2 things:
1. It marks any and all `Deny` policies as not in use. Which makes sense, but not sure it's what one would expect. I thought about changing that, but wanted to hear your thoughts first.
2. The permission `iam:PassRole` isn't marked by AWS Access Advisor as IAM usage. I raised this with AWS support and they said there's an internal ticket about it. Question is - should cloudmapper mark this in some way?
I'll be happy to implement both, I'm just not sure what's the correct approach to them. I'll be happy to hear your thoughts!
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.