Commit e2420b1793
Verified · cmc
Layout: unified · split
README.nfo deleted −81
| @@ -1,81 +0,0 @@ | |||
| 1 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 2 | │ A W S S U M M A R Y [ KRZ ] krz.sh │ | ||
| 3 | └──────────────────────────────────────────────────────────────┘ | ||
| 4 | |||
| 5 | WHAT | ||
| 6 | python tool. sends one plaintext email a day summarizing an aws | ||
| 7 | account: billing, security hub findings, route 53 health checks, | ||
| 8 | cloudwatch alarms, s3 audit, expiring acm certs, config compliance, | ||
| 9 | cloudfront changes, waf blocks. | ||
| 10 | |||
| 11 | built for solo or small-team accounts. add a section by dropping | ||
| 12 | new_section.py in sections/ and listing it in config.toml. | ||
| 13 | |||
| 14 | CONFIGURE | ||
| 15 | edit config.toml: | ||
| 16 | |||
| 17 | [aws] | ||
| 18 | profile = "default" | ||
| 19 | region = "us-east-1" | ||
| 20 | |||
| 21 | [email] | ||
| 22 | from = "you@example.com" | ||
| 23 | to = ["you@example.com"] | ||
| 24 | subject = "Daily AWS Report" | ||
| 25 | |||
| 26 | [report] | ||
| 27 | sections = ["acm"] | ||
| 28 | |||
| 29 | no aws profile yet: | ||
| 30 | |||
| 31 | aws configure --profile default | ||
| 32 | |||
| 33 | RUN | ||
| 34 | python main.py | ||
| 35 | |||
| 36 | or with uv (installs deps, makes a venv): | ||
| 37 | |||
| 38 | uv run main.py | ||
| 39 | |||
| 40 | emails are plaintext with ascii tables via tabulate. | ||
| 41 | |||
| 42 | INSTALL | ||
| 43 | python 3.11+. | ||
| 44 | |||
| 45 | pip install -r requirements.txt | ||
| 46 | # or: uv sync | ||
| 47 | |||
| 48 | needs boto3 and tabulate. the iam user or role needs read access to | ||
| 49 | cost explorer, security hub, s3, cloudfront, cloudwatch, route 53, | ||
| 50 | acm, config, waf, and ses if sending from aws. | ||
| 51 | |||
| 52 | STRUCTURE | ||
| 53 | config.toml aws profile, region, email, report options | ||
| 54 | main.py entry point; builds and sends the report | ||
| 55 | email_formatter.py formats the email body | ||
| 56 | utils.py shared helpers | ||
| 57 | pyproject.toml metadata and dependencies | ||
| 58 | sections/ one generator per section | ||
| 59 | acm.py expiring certs | ||
| 60 | cloudfront.py distribution changes | ||
| 61 | cloudwatch.py alarms | ||
| 62 | config.py config compliance | ||
| 63 | costexplorer.py billing | ||
| 64 | route53.py health checks | ||
| 65 | s3.py bucket audit | ||
| 66 | securityhub.py findings | ||
| 67 | |||
| 68 | each section implements get_section(config) -> str. add, remove, or | ||
| 69 | order sections in config.toml. | ||
| 70 | |||
| 71 | TODO | ||
| 72 | - csv or html export | ||
| 73 | - slack or teams notifications | ||
| 74 | - lambda deployment | ||
| 75 | |||
| 76 | LICENSE | ||
| 77 | 0bsd. see LICENSE. | ||
| 78 | |||
| 79 | ┌──────────────────────────────────────────────────────────────┐ | ||
| 80 | │ krz.sh │ | ||
| 81 | └──────────────────────────────────────────────────────────────┘ | ||
README.org added +91
| @@ -0,0 +1,91 @@ | |||
| 1 | #+title: aws summary | ||
| 2 | |||
| 3 | * what | ||
| 4 | python tool. sends one plaintext email a day summarizing an aws | ||
| 5 | account: billing, security hub findings, route 53 health checks, | ||
| 6 | cloudwatch alarms, s3 audit, expiring acm certs, config compliance, | ||
| 7 | cloudfront changes, waf blocks. | ||
| 8 | |||
| 9 | built for solo or small-team accounts. add a section by dropping | ||
| 10 | new_section.py in sections/ and listing it in config.toml. | ||
| 11 | |||
| 12 | * configure | ||
| 13 | edit config.toml: | ||
| 14 | |||
| 15 | #+begin_src conf | ||
| 16 | [aws] | ||
| 17 | profile = "default" | ||
| 18 | region = "us-east-1" | ||
| 19 | #+end_src | ||
| 20 | |||
| 21 | #+begin_src conf | ||
| 22 | [email] | ||
| 23 | from = "you@example.com" | ||
| 24 | to = ["you@example.com"] | ||
| 25 | subject = "Daily AWS Report" | ||
| 26 | #+end_src | ||
| 27 | |||
| 28 | #+begin_src conf | ||
| 29 | [report] | ||
| 30 | sections = ["acm"] | ||
| 31 | #+end_src | ||
| 32 | |||
| 33 | no aws profile yet: | ||
| 34 | |||
| 35 | #+begin_src sh | ||
| 36 | aws configure --profile default | ||
| 37 | #+end_src | ||
| 38 | |||
| 39 | * run | ||
| 40 | #+begin_src sh | ||
| 41 | python main.py | ||
| 42 | #+end_src | ||
| 43 | |||
| 44 | or with uv (installs deps, makes a venv): | ||
| 45 | |||
| 46 | #+begin_src sh | ||
| 47 | uv run main.py | ||
| 48 | #+end_src | ||
| 49 | |||
| 50 | emails are plaintext with ascii tables via tabulate. | ||
| 51 | |||
| 52 | * install | ||
| 53 | python 3.11+. | ||
| 54 | |||
| 55 | #+begin_src sh | ||
| 56 | pip install -r requirements.txt | ||
| 57 | # or: uv sync | ||
| 58 | #+end_src | ||
| 59 | |||
| 60 | needs boto3 and tabulate. the iam user or role needs read access to | ||
| 61 | cost explorer, security hub, s3, cloudfront, cloudwatch, route 53, | ||
| 62 | acm, config, waf, and ses if sending from aws. | ||
| 63 | |||
| 64 | * structure | ||
| 65 | #+begin_example | ||
| 66 | config.toml aws profile, region, email, report options | ||
| 67 | main.py entry point; builds and sends the report | ||
| 68 | email_formatter.py formats the email body | ||
| 69 | utils.py shared helpers | ||
| 70 | pyproject.toml metadata and dependencies | ||
| 71 | sections/ one generator per section | ||
| 72 | acm.py expiring certs | ||
| 73 | cloudfront.py distribution changes | ||
| 74 | cloudwatch.py alarms | ||
| 75 | config.py config compliance | ||
| 76 | costexplorer.py billing | ||
| 77 | route53.py health checks | ||
| 78 | s3.py bucket audit | ||
| 79 | securityhub.py findings | ||
| 80 | #+end_example | ||
| 81 | |||
| 82 | each section implements get_section(config) -> str. add, remove, or | ||
| 83 | order sections in config.toml. | ||
| 84 | |||
| 85 | * todo | ||
| 86 | - csv or html export | ||
| 87 | - slack or teams notifications | ||
| 88 | - lambda deployment | ||
| 89 | |||
| 90 | * license | ||
| 91 | 0bsd. see LICENSE. | ||