Commit e2420b1793
Verified · cmc
Layout: unified · split
README.nfo deleted −81
| @@ -1,81 +0,0 @@ | ||
| 1 | ┌──────────────────────────────────────────────────────────────┐ | |
| 2 | │ A W S S U M M A R Y [ KRZ ] krz.sh │ | |
| 3 | └──────────────────────────────────────────────────────────────┘ | |
| 4 | ||
| 5 | WHAT | |
| 6 | python tool. sends one plaintext email a day summarizing an aws | |
| 7 | account: billing, security hub findings, route 53 health checks, | |
| 8 | cloudwatch alarms, s3 audit, expiring acm certs, config compliance, | |
| 9 | cloudfront changes, waf blocks. | |
| 10 | ||
| 11 | built for solo or small-team accounts. add a section by dropping | |
| 12 | new_section.py in sections/ and listing it in config.toml. | |
| 13 | ||
| 14 | CONFIGURE | |
| 15 | edit config.toml: | |
| 16 | ||
| 17 | [aws] | |
| 18 | profile = "default" | |
| 19 | region = "us-east-1" | |
| 20 | ||
| 21 | [email] | |
| 22 | from = "you@example.com" | |
| 23 | to = ["you@example.com"] | |
| 24 | subject = "Daily AWS Report" | |
| 25 | ||
| 26 | [report] | |
| 27 | sections = ["acm"] | |
| 28 | ||
| 29 | no aws profile yet: | |
| 30 | ||
| 31 | aws configure --profile default | |
| 32 | ||
| 33 | RUN | |
| 34 | python main.py | |
| 35 | ||
| 36 | or with uv (installs deps, makes a venv): | |
| 37 | ||
| 38 | uv run main.py | |
| 39 | ||
| 40 | emails are plaintext with ascii tables via tabulate. | |
| 41 | ||
| 42 | INSTALL | |
| 43 | python 3.11+. | |
| 44 | ||
| 45 | pip install -r requirements.txt | |
| 46 | # or: uv sync | |
| 47 | ||
| 48 | needs boto3 and tabulate. the iam user or role needs read access to | |
| 49 | cost explorer, security hub, s3, cloudfront, cloudwatch, route 53, | |
| 50 | acm, config, waf, and ses if sending from aws. | |
| 51 | ||
| 52 | STRUCTURE | |
| 53 | config.toml aws profile, region, email, report options | |
| 54 | main.py entry point; builds and sends the report | |
| 55 | email_formatter.py formats the email body | |
| 56 | utils.py shared helpers | |
| 57 | pyproject.toml metadata and dependencies | |
| 58 | sections/ one generator per section | |
| 59 | acm.py expiring certs | |
| 60 | cloudfront.py distribution changes | |
| 61 | cloudwatch.py alarms | |
| 62 | config.py config compliance | |
| 63 | costexplorer.py billing | |
| 64 | route53.py health checks | |
| 65 | s3.py bucket audit | |
| 66 | securityhub.py findings | |
| 67 | ||
| 68 | each section implements get_section(config) -> str. add, remove, or | |
| 69 | order sections in config.toml. | |
| 70 | ||
| 71 | TODO | |
| 72 | - csv or html export | |
| 73 | - slack or teams notifications | |
| 74 | - lambda deployment | |
| 75 | ||
| 76 | LICENSE | |
| 77 | 0bsd. see LICENSE. | |
| 78 | ||
| 79 | ┌──────────────────────────────────────────────────────────────┐ | |
| 80 | │ krz.sh │ | |
| 81 | └──────────────────────────────────────────────────────────────┘ | |
README.org added +91
| @@ -0,0 +1,91 @@ | ||
| 1 | #+title: aws summary | |
| 2 | ||
| 3 | * what | |
| 4 | python tool. sends one plaintext email a day summarizing an aws | |
| 5 | account: billing, security hub findings, route 53 health checks, | |
| 6 | cloudwatch alarms, s3 audit, expiring acm certs, config compliance, | |
| 7 | cloudfront changes, waf blocks. | |
| 8 | ||
| 9 | built for solo or small-team accounts. add a section by dropping | |
| 10 | new_section.py in sections/ and listing it in config.toml. | |
| 11 | ||
| 12 | * configure | |
| 13 | edit config.toml: | |
| 14 | ||
| 15 | #+begin_src conf | |
| 16 | [aws] | |
| 17 | profile = "default" | |
| 18 | region = "us-east-1" | |
| 19 | #+end_src | |
| 20 | ||
| 21 | #+begin_src conf | |
| 22 | [email] | |
| 23 | from = "you@example.com" | |
| 24 | to = ["you@example.com"] | |
| 25 | subject = "Daily AWS Report" | |
| 26 | #+end_src | |
| 27 | ||
| 28 | #+begin_src conf | |
| 29 | [report] | |
| 30 | sections = ["acm"] | |
| 31 | #+end_src | |
| 32 | ||
| 33 | no aws profile yet: | |
| 34 | ||
| 35 | #+begin_src sh | |
| 36 | aws configure --profile default | |
| 37 | #+end_src | |
| 38 | ||
| 39 | * run | |
| 40 | #+begin_src sh | |
| 41 | python main.py | |
| 42 | #+end_src | |
| 43 | ||
| 44 | or with uv (installs deps, makes a venv): | |
| 45 | ||
| 46 | #+begin_src sh | |
| 47 | uv run main.py | |
| 48 | #+end_src | |
| 49 | ||
| 50 | emails are plaintext with ascii tables via tabulate. | |
| 51 | ||
| 52 | * install | |
| 53 | python 3.11+. | |
| 54 | ||
| 55 | #+begin_src sh | |
| 56 | pip install -r requirements.txt | |
| 57 | # or: uv sync | |
| 58 | #+end_src | |
| 59 | ||
| 60 | needs boto3 and tabulate. the iam user or role needs read access to | |
| 61 | cost explorer, security hub, s3, cloudfront, cloudwatch, route 53, | |
| 62 | acm, config, waf, and ses if sending from aws. | |
| 63 | ||
| 64 | * structure | |
| 65 | #+begin_example | |
| 66 | config.toml aws profile, region, email, report options | |
| 67 | main.py entry point; builds and sends the report | |
| 68 | email_formatter.py formats the email body | |
| 69 | utils.py shared helpers | |
| 70 | pyproject.toml metadata and dependencies | |
| 71 | sections/ one generator per section | |
| 72 | acm.py expiring certs | |
| 73 | cloudfront.py distribution changes | |
| 74 | cloudwatch.py alarms | |
| 75 | config.py config compliance | |
| 76 | costexplorer.py billing | |
| 77 | route53.py health checks | |
| 78 | s3.py bucket audit | |
| 79 | securityhub.py findings | |
| 80 | #+end_example | |
| 81 | ||
| 82 | each section implements get_section(config) -> str. add, remove, or | |
| 83 | order sections in config.toml. | |
| 84 | ||
| 85 | * todo | |
| 86 | - csv or html export | |
| 87 | - slack or teams notifications | |
| 88 | - lambda deployment | |
| 89 | ||
| 90 | * license | |
| 91 | 0bsd. see LICENSE. | |