duo-labs / duo-labs/cloudmapper

iam_report identifies unused incorrectly

Open
#678 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
6.3k
Forks
836
PR merge metrics
No merged PRs in 30d

Description

Hey!

I've been using the iam_report, and it's really handy for me. I tried to rightsize my IAM according to the report, and found 2 things:
1. It marks any and all `Deny` policies as not in use. Which makes sense, but not sure it's what one would expect. I thought about changing that, but wanted to hear your thoughts first.
2. The permission `iam:PassRole` isn't marked by AWS Access Advisor as IAM usage. I raised this with AWS support and they said there's an internal ticket about it. Question is - should cloudmapper mark this in some way?

I'll be happy to implement both, I'm just not sure what's the correct approach to them. I'll be happy to hear your thoughts!

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.