krz/aws-summary-report

Automated AWS summary reports, straight to your inbox. automation aws email reporting

README.org

main
aws-summary-report/README.org rendered · source · history · blame · raw

91 lines · 2030 bytes

 1#+title: aws summary
 2
 3* what
 4python tool. sends one plaintext email a day summarizing an aws
 5account: billing, security hub findings, route 53 health checks,
 6cloudwatch alarms, s3 audit, expiring acm certs, config compliance,
 7cloudfront changes, waf blocks.
 8
 9built for solo or small-team accounts. add a section by dropping
10new_section.py in sections/ and listing it in config.toml.
11
12* configure
13edit config.toml:
14
15#+begin_src conf
16[aws]
17profile = "default"
18region = "us-east-1"
19#+end_src
20
21#+begin_src conf
22[email]
23from = "you@example.com"
24to = ["you@example.com"]
25subject = "Daily AWS Report"
26#+end_src
27
28#+begin_src conf
29[report]
30sections = ["acm"]
31#+end_src
32
33no aws profile yet:
34
35#+begin_src sh
36aws configure --profile default
37#+end_src
38
39* run
40#+begin_src sh
41python main.py
42#+end_src
43
44or with uv (installs deps, makes a venv):
45
46#+begin_src sh
47uv run main.py
48#+end_src
49
50emails are plaintext with ascii tables via tabulate.
51
52* install
53python 3.11+.
54
55#+begin_src sh
56pip install -r requirements.txt
57# or: uv sync
58#+end_src
59
60needs boto3 and tabulate. the iam user or role needs read access to
61cost explorer, security hub, s3, cloudfront, cloudwatch, route 53,
62acm, config, waf, and ses if sending from aws.
63
64* structure
65#+begin_example
66config.toml          aws profile, region, email, report options
67main.py              entry point; builds and sends the report
68email_formatter.py   formats the email body
69utils.py             shared helpers
70pyproject.toml       metadata and dependencies
71sections/            one generator per section
72  acm.py             expiring certs
73  cloudfront.py      distribution changes
74  cloudwatch.py      alarms
75  config.py          config compliance
76  costexplorer.py    billing
77  route53.py         health checks
78  s3.py              bucket audit
79  securityhub.py     findings
80#+end_example
81
82each section implements get_section(config) -> str. add, remove, or
83order sections in config.toml.
84
85* todo
86- csv or html export
87- slack or teams notifications
88- lambda deployment
89
90* license
910bsd. see LICENSE.