Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

1,141 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

AI Tracker

Objective

Track how long it takes and how much it costs to create projects with AI πŸ€– in an attempt to optimize progress. Note that I have only been using Opus 6 and 8 same price per token. I have been trying to log my time but there are some gaps where I was working but making no progress because I'm fixing things that are broken or reworking code. Part of the rework is the model failing write the code as specifed. Part of it is my rearchitecting my data model after testing. See notes for details and time tracking file where I've strated tracking some (not all) rework.

Status Legend

Status Description
🟒 Done
🟑 Broken
πŸ”΄ Not attempted

Tracker Diagram Generated By Application

This is just the particular configuration I'm tesing. The configuration supports any AWS resources and account structure.

~~ Right now the reoprting below is a bit messed up so what is shown below is no longer accurate. I'll update it shortly. As explained on social media and in the details of the mistakes, fixed, and time tracking mds, I'm revamping the architecture to overcome some concurrency issues. I've pretty much fixed the concurrency issues and tracker diagram creation - though I have some slowness to address. Though it's "working" to some degree, I have to fix a role assumption issue (mfa v no mfa before trust policy is updated), diagram slowness, an eternal loop on certain resources, and the individual resource issues). More in mistakes.md. I'll update this hoepfully shortly.

=========================================
 xxxxxx: Deploy Diagram
=========================================
🟑 org: xxxxxxx (xxxxxxxx)
|
|     Organization Resources:
|____ 🟒 Organization (xxxxxxxx)
|____ 🟒 Enable All Features (xxxxxxxx)
|____ 🟒 Deny-All OU (xxxxxxxx)
|____ 🟒 SCP Require IMDSv2 (xxxxxxxx)
|____ 🟒 SCP Deny Leave Org (xxxxxxxx)
|____ 🟒 SCP Allowed Regions (xxxxxxxx)
|
|____ 🟑 env: manage
|     |
|     |     Environment Resources:
|     |____ 🟒 OU (xxxxxxxx)
|     |____ 🟒 SCP Deny External (xxxxxxxx)
|     |
|     |____ 🟒 account: manage-iam (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ πŸ”΄ Move account to OU
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |           |____ 🟒 iadmin-user (xxxxxxxx)
|     |           |____ 🟒 xadmin-user (xxxxxxxx)
|     |
|     |____ 🟒 account: manage-kms (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ πŸ”΄ Move account to OU
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |           |____ 🟒 kms-logs-key (xxxxxxxx)
|     |           |____ 🟒 kms-auth-key (xxxxxxxx)
|     |           |____ 🟒 kms-jobs-key (xxxxxxxx)
|     |           |____ 🟒 kms-secrets-key (xxxxxxxx)
|     |           |____ 🟒 kms-config-key (xxxxxxxx)
|     |
|     |____ 🟒 account: manage-security (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ 🟒 Delegate Security Hub admin (xxxxxxxx)
|     |     |____ 🟒 Delegate GuardDuty admin (xxxxxxxx)
|     |     |____ 🟒 Delegate CloudTrail admin (xxxxxxxx)
|     |     |____ 🟒 Delegate AWS Config admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Macie admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Inspector admin (xxxxxxxx)
|     |     |____ 🟒 Delegate IAM Access Analyzer admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Audit Manager admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Health admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Detective admin (xxxxxxxx)
|     |     |____ 🟒 Configure GuardDuty (xxxxxxxx)
|     |     |____ 🟒 Configure CloudTrail (xxxxxxxx)
|     |     |____ 🟒 Configure AWS Config (xxxxxxxx)
|     |     |____ 🟒 Configure Macie (xxxxxxxx)
|     |     |____ 🟒 Configure Inspector (xxxxxxxx)
|     |     |____ 🟒 Configure IAM Access Analyzer (xxxxxxxx)
|     |     |____ 🟒 Configure Security Alerts (xxxxxxxx)
|     |     |____ 🟒 Move account to OU (xxxxxxxx)
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |           |____ 🟒 s3-log-bucket (xxxxxxxx)
|     |           |____ 🟒 configure-security-hub (xxxxxxxx)
|     |           |____ 🟒 s3-log-bucket-policy (xxxxxxxx)
|     |
|     |____ 🟒 account: manage-org (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ 🟒 Org resource policy (xxxxxxxx)
|     |     |____ 🟒 Move account to OU (xxxxxxxx)
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |           |____ 🟒 delegate-org-admin (xxxxxxxx)
|     |
|     |____ 🟒 account: manage-accounting (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ 🟒 Delegate Cost Optimization Hub admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Compute Optimizer admin (xxxxxxxx)
|     |     |____ 🟒 Move account to OU (xxxxxxxx)
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |
|     |____ 🟒 account: manage-ipam (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ 🟒 Delegate IPAM admin (xxxxxxxx)
|     |     |____ 🟒 IPAM (xxxxxxxx)
|     |     |____ 🟒 Delegate Network Manager admin (xxxxxxxx)
|     |     |____ 🟒 Delegate VPC Reachability Analyzer admin (xxxxxxxx)
|     |     |____ 🟒 Delegate Firewall Manager admin (xxxxxxxx)
|     |     |____ πŸ”΄ Move account to OU
|     |     |____ 🟒 Account alias (xxxxxxxx)
|     |     |____ 🟒 Xadmin role (xxxxxxxx)
|     |     |____ 🟒 Iadmin role (xxxxxxxx)
|     |     |____ 🟒 Oadmin role (xxxxxxxx)
|     |     |____ 🟒 Account Budget (xxxxxxxx)
|     |     |____ 🟒 Delete default VPCs (xxxxxxxx)
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |
|     |____ 🟑 account: manage-kiro (xxxxxxxx)
|           |
|           |     Resources:
|           |____ πŸ”΄ kiro-cli-identity-center
|           |____ πŸ”΄ Move account to OU
|           |____ 🟒 Account alias (xxxxxxxx)
|           |____ πŸ”΄ Xadmin role
|           |____ 🟑 Iadmin role (error)
|           |     ↳ ERROR: exit-conditions.sh failed for iadmin-role. [...renamed account problem]
|           |____ 🟑 Oadmin role (error)
|           |     ↳ ERROR: deployment of oadmin-role failed. [...renamed account problem]
|           |____ 🟑 Account Budget (error)
|           |     ↳ ERROR: deployment of account-budget failed.[...renamed account problem]
|           |____ 🟒 Delete default VPCs (xxxxxxxx)
|           |
|           |____ region: us-east-2
|                 |     Resources:
|
|____ 🟑 env: backup
|     |
|     |     Environment Resources:
|     |____ πŸ”΄ OU
|     |____ πŸ”΄ SCP Deny External
|     |
|     |____ 🟑 account: backup-work-test (xxxxxxxx)
|     |     |
|     |     |     Resources:
|     |     |____ 🟒 Delegate Backup admin (xxxxxxxx)
|     |     |____ πŸ”΄ Move account to OU
|     |     |____ 🟑 Account alias (error)
|     |     |     ↳ ERROR: Failed to list aliases
|     |     |____ 🟑 Xadmin role (error)
|     |     |     ↳ ERROR: deployment of xadmin-role failed. [...renamed account problem]
|     |     |____ 🟑 Iadmin role (error)
|     |     |     ↳ ERROR: deployment of iadmin-role failed. [...renamed account problem]
|     |     |____ 🟑 Oadmin role (error)
|     |     |     ↳ ERROR: exit-conditions.sh failed for oadmin-role. [...renamed account problem]
|     |     |____ 🟑 Account Budget (error)
|     |     |     ↳ ERROR: deployment of account-budget failed. org=o-vif30ez4ew env=backup account=backup-work-test 
|     |     |       resource=account-budget action=deploy [...renamed account problem]
|     |     |____ 🟑 Delete default VPCs (error)
|     |     |     ↳ ERROR: deployment of delete-default-vpcs failed. o[...renamed account problem]
|     |     |
|     |     |____ region: us-east-2
|     |           |     Resources:
|     |           |____ πŸ”΄ backup-work-test
|     |           |____ 🟑 kms-backup-key (error)
|     |           |     ↳ ERROR: parallel run aborted: [...renamed account problem]
|     |
|     |____ πŸ”΄ account: backup-manage
|           |
|           |     Resources:
|           |____ πŸ”΄ Move account to OU
|           |____ πŸ”΄ Account alias
|           |____ πŸ”΄ Xadmin role
|           |____ πŸ”΄ Iadmin role
|           |____ πŸ”΄ Oadmin role
|           |____ πŸ”΄ Account Budget
|           |____ πŸ”΄ Delete default VPCs
|
|____ πŸ”΄ env: deny-all
|     |
|     |     Environment Resources:
|     |____ πŸ”΄ SCP Always Denied Actions
|     |____ πŸ”΄ OU
|     |____ πŸ”΄ SCP Deny External
|
|____ πŸ”΄ env: work-test
      |
      |     Environment Resources:
      |____ πŸ”΄ OU
      |____ 🟒 SCP Deny External (xxxxxxxx)
      |
      |____ 🟒 account: work-test-iam
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ Iadmin user
      |     |____ πŸ”΄ Move account to OU
      |     |____ πŸ”΄ Account alias
      |     |____ 🟒 Xadmin role (xxxxxxxx)
      |     |____ 🟒 Iadmin role (xxxxxxxx)
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |     |
      |     |____ region: us-east-2
      |           |     Resources:
      |           |____ 🟒 xadmin-user (xxxxxxxx)
      |
      |____ πŸ”΄ account: work-test-kms
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ KMS Secrets Key
      |     |____ πŸ”΄ Move account to OU
      |     |____ 🟒 Account alias (xxxxxxxx)
      |     |____ πŸ”΄ Xadmin role
      |     |____ πŸ”΄ Iadmin role
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |     |
      |     |____ region: us-east-2
      |           |     Resources:
      |           |____ 🟒 kms-jobs-key (xxxxxxxx)
      |           |____ πŸ”΄ kms-ami-key
      |
      |____ πŸ”΄ account: work-test-network
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ Move account to OU
      |     |____ πŸ”΄ Account alias
      |     |____ πŸ”΄ Xadmin role
      |     |____ πŸ”΄ Iadmin role
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |     |
      |     |____ region: us-east-2
      |           |     Resources:
      |           |____ 🟒 remote-access-prefix-list (xxxxxxxx)
      |           |____ πŸ”΄ auth-vpc
      |           |____ πŸ”΄ work-vpc
      |           |____ πŸ”΄ honeypot-vpc
      |           |____ πŸ”΄ backup-vpc
      |           |____ 🟒 ipam-pool (xxxxxxxx)
      |           |____ 🟒 vpc-flow-logs-role (xxxxxxxx)
      |           |____ πŸ”΄ jobs-vpc
      |
      |____ πŸ”΄ account: work-test-ami
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ Move account to OU
      |     |____ πŸ”΄ Account alias
      |     |____ πŸ”΄ Xadmin role
      |     |____ πŸ”΄ Iadmin role
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |     |
      |     |____ region: us-east-2
      |           |     Resources:
      |           |____ πŸ”΄ collab-ami
      |           |____ πŸ”΄ base-ubuntu-ami
      |           |____ πŸ”΄ share-amis-to-ou
      |           |____ πŸ”΄ base-amazon-linux-ami
      |           |____ πŸ”΄ share-ami
      |
      |____ 🟒 account: work-test-repo
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ Move account to OU
      |     |____ πŸ”΄ Account alias
      |     |____ πŸ”΄ Xadmin role
      |     |____ πŸ”΄ Iadmin role
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |     |
      |     |____ region: us-east-2
      |           |     Resources:
      |           |____ 🟒 code-commit-repository (xxxxxxxx)
      |
      |____ πŸ”΄ account: work-test-domains
      |     |
      |     |     Resources:
      |     |____ πŸ”΄ Move account to OU
      |     |____ πŸ”΄ Account alias
      |     |____ πŸ”΄ Xadmin role
      |     |____ πŸ”΄ Iadmin role
      |     |____ πŸ”΄ Oadmin role
      |     |____ πŸ”΄ Account Budget
      |     |____ πŸ”΄ Delete default VPCs
      |
      |____ πŸ”΄ account: work-test-project-alnzbinsdvnasaosfil
            |
            |     Resources:
            |____ πŸ”΄ Move account to OU
            |____ πŸ”΄ Account alias
            |____ πŸ”΄ Xadmin role
            |____ πŸ”΄ Iadmin role
            |____ πŸ”΄ Oadmin role
            |____ πŸ”΄ Account Budget
            |____ πŸ”΄ Delete default VPCs
            |
            |____ region: us-east-2
                  |     Resources:
                  |____ πŸ”΄ work-test-project-alnzbinsdvnasaosfil

Status Summary

Status Description
🟒 Configure Reosurce Types
🟒 Organization
🟑 Deploy Environment & Resources
🟑 Verify Environment & Resources
🟑 Delete Environent & Resources
πŸ”΄ Manage Drift
🟑 Packaged Code
🟑 QA
πŸ”΄ Code Review
πŸ”΄ Security Testing

Token / Credit Usage

Usage Dates Plan % usage charges days cost per day
June 1 - 12 $200 plan 100% $83 12 $6.92
June 13 - 17 9:00 pm $200 plan 100% $67 4 $16.75
June 17 9:16PM - 23 3:00 AM $200 plan 100% $120 6 $20
June 24 - 28 2:15 AM $200 plan 100% $134.16 4 $33.54
June 30 - July 1 partial $200 plan ? $53.55 < 1 $53.55

Total Kiro charged for June: $457.71

Note that I started a new $200 plan on the last day of June presumably a few hours before the UTC rollover time and the balance between what I was billed the full month and what I was billed prior to that was $53.55. Which equates to something like $20 per hour of churning nonsense since the models were going haywire at that point and didn't accomplish the current objective I was working on and was getting tons of noops. this was right after Fable came out. Happens every time a new Anthropic model comes out whether I have access to it or not.

Usage Dates Plan % usage charges days cost per day
July 1 - 2 4:00 AM $200 plan 100% $12.90 2 $6.45
July 2 - July 3 $200 plan 100% $181 2 $90.5

I stopped posting here. I'm using a $200 plan about every 2 days now. I think I've spent another $200. Up to $1000 for the mont and it's July 10th. Still not done.

Support this research

If you want to support of follow this research consider becoming a paid subscriber on my substack technology and security research blog. Paid subscribers can add comments and see the archives. Founding members can ask questions (i.e. consulting or training). You can also just sign up for free - no worries! All are welcome and appreciated. 🩡

https://teriradichel.substack.com

Project Objective: AWS Bootstrap Script for AI Agent Environment

Build a script to deploy, delete, and test an AWS environment to securely run AI agents. Specifically I want to segregate my security testing, development, production, and management environments. The framework also sets up my organization with monitoring including budgets and security services used by delegated administrators (Guard Duty, etc.)

The whole point of this is to be able to quickly spin up and tear down environments for projects. As for agents I want to be able to quickly deploy new ideas. That is in part achieved by my job framework which is the follow-on project to this one, but I need first and foremost to have the secure base infrastructure in which to deploy my agent framework and agent resources.

I also spin up separate environments for each penetration test so one test cannot affect another. If I am running AI agents in an environment and they mess it up, I can tear down the whole environment and rebuild it easily. In addition, it ensures that my agents cannot affect production resources with proper security boundaries. When something is deployed incorrectly or I have a billing issue I cannot fix, I can tear down the environment to stop the building and build a new one.

A full series on what I am developing in this project can be found here:

https://teriradichel.substack.com/p/toc-aws-organizations-and-ai-agent

More granular updates on X @teriradichel and the AWS Builder Center.

https://builder.aws.com/profile?tab=articles

Tools and models

I'm primarily using Kiro CLI and anthropic models, though I do use Google aimode to ask questions at times and may branch out to test other models and technologies after this infrastructure is up and running.

Issues:

https://github.com/2ndSightLab/ai-tracker/blob/main/issues.md

Fixed / Notes:

https://github.com/2ndSightLab/ai-tracker/blob/main/fixed.md

AWS Wishlist

https://github.com/2ndSightLab/ai-tracker/blob/main/awswishlist.md

My Time

I started this project around March 7th. I had to take a break for about three weeks in May. I haven't really worked on anything else besides this and blog posts because I keep thinking it is "almost done." I've also been working kind of long hours to do it and figure things out.

My initial post on this project tracks the start project and initial progress in 2.5 weeks

https://teriradichel.substack.com/p/what-ive-vibe-coded-in-25-weeks

The time it takes is demonstrated by feature completion and the timestamps in this GitHub repo, though my time may be taken away for other things periodically.

Response Time

Sometimes I am blocked by the system being slow or copmletely unsuable. It's hard to tell if it's the model or Kiro so I tried to measure gaps. This is a work in progress. I have limited information to work with, which I think needs to improve. We need more transparency for all metrics.

https://github.com/2ndSightLab/ai-tracker/blob/main/response-time.md

Cost:

Costs while building an AI Agent Bootstrap Script and Framework

Date Range: Mar 7, 2026 - Jul 2, 2026

Service / Resource Total Mar 2026 Apr 2026 May 2026 Jun 2026 Jul 2026*
Total costs $2,151.92 $359.07 $387.55 $621.52 $755.02 $28.76
Kiro $1,079.02 $193.55 $129.07 $285.79 $457.71 $12.90
Virtual Private Cloud $411.17 $50.07 $118.34 $137.58 $104.22 $0.97
Elastic Compute Cloud - Compute $283.88 $39.45 $44.28 $100.12 $96.80 $3.23

Costs broken down by service and other details here:

https://github.com/2ndSightLab/ai-tracker/blob/main/cost.md

Details

I was tracking all this manually but now I ahve the tracker diagram above to track deployments. But notice I haven't spent much time on actually security testing or code review. I review the code as it's being writtne a lot. I have crucial pieces of code that I move to other projects and lock down and some of that has been reviewed a bit more.

Bootrstrap Role

Bootstrap Role Script

Role, policy and permission boundary deployed in root management account in AWS CloudShell.

Feature Deploy Delete Verify Tested Code Review Security Review
Role 🟒 🟒 🟒 🟒 🟒 🟒
Policy 🟒 🟒 🟒 🟒 🟒 🟒
Permission Boundary 🟒 🟒 🟒 🟒 🟒 πŸ”΄
Trust policy with MFA and IP condition 🟒 🟒 🟒 🟒 🟒 🟒

Shared Code Projects

AWS CLI Auth with MFA

Separate reusable project that handles configuring role profiles and role assumption with MFA.

I used some previously written code as a starting point in which the role trust policies contain MFA and IPAddress conditions to assume the role and the user associated with the keys cannot do anything except asusme a role with MFA. I found at some point the CLI Auth code in my AI repos was modified to cache creds. I thought I removed that in the original repo. Do your own code review.

Feature Tested Code Review Security Review
Configure Role Profile 🟒 🟒 🟒
Assume Role With MFA 🟒 🟑 🟑

XML Parser

A generic XML parser project that can be used by any bash project to move error prone and vulnerability prone code to a spearate locked down project.

Feature Tested Code Review Security Review
XML read by path 🟒 πŸ”΄ πŸ”΄
XML write by path 🟒 πŸ”΄ πŸ”΄
XML load by path 🟒 πŸ”΄ πŸ”΄
XML read by single value 🟒 πŸ”΄ πŸ”΄
XML write by single value 🟒 πŸ”΄ πŸ”΄
XML load by single value 🟒 πŸ”΄ πŸ”΄

Menus

Separate reusable project provides simple and xml driven menus for consistency and easy updates

Feature Tested Code Review Security Review
Reusaable Numbered Menu with Filter by letters 🟒 πŸ”΄ πŸ”΄
Reusable y/n/e prompt 🟒 πŸ”΄ πŸ”΄
XML data driven Menu 🟒 πŸ”΄ πŸ”΄
Multi-select menu 🟒 πŸ”΄ πŸ”΄
/c to return to previous menu 🟒 πŸ”΄ πŸ”΄
common banner with lines above and below and text between 🟒 πŸ”΄ πŸ”΄

AWS Command Runner

Feature Tested Code Review Security Review
Run AWS Command 🟒 πŸ”΄ πŸ”΄
Track Deployed Resources 🟒 πŸ”΄ πŸ”΄
Switch Role (org/acount) 🟒 πŸ”΄ πŸ”΄

Time tracker

Feature Tested Code Review Security Review
Analysis Report 🟒 πŸ”΄ πŸ”΄
Report time (logs per day) 🟒 πŸ”΄ πŸ”΄
Report mistake (logs per day) 🟒 πŸ”΄ πŸ”΄
Bug Report 🟒 πŸ”΄ πŸ”΄
Run all tests (all projects) 🟒 πŸ”΄ πŸ”΄

Global Requirements

Feature Done
Cross-Project Requiremetns and Logging 🟒

Test Runner

Feature Done
Run test for all projects 🟒

Bootstrap Code

Bootstrap Orchestrator

A project to manaage te handoff from org to environnet project so neither depends on the other. Reduces context and scope of the org and environment projects.

Feature Tested Code Review Security Review
Configure Org Types (Menu Action) 🟒 πŸ”΄ πŸ”΄
Configure Org (Menu Action) 🟒 πŸ”΄ πŸ”΄
Deploy Resources (Menu Action) 🟒 πŸ”΄ πŸ”΄
Manage Drift (Menu Action) 🟒 πŸ”΄ πŸ”΄

Configure Organization Types

Configure organization to deploy; define environemnt types (allowed resources)

  • Environment Types Define accounts and resources that can be deployed to an environment.
  • Accounts define resources that can be deployed to account on top of environmen resources.
  • The resource master list maps a reosurce to a script that deploys it (to create a menu of resources to deploy)
Feature List Add Delete Rename Edit Menus Tested Code Review Security Review
Resource Types 🟒 🟒 🟒 🟒 n/a 🟒 🟒 πŸ”΄ πŸ”΄
Account Types 🟒 🟒 🟒 n/a 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Account Resource Types 🟒 🟒 🟒 🟒 n/a 🟒 🟒 πŸ”΄ πŸ”΄
Environment Types 🟒 🟒 🟒 🟒 n/a 🟒 🟒 πŸ”΄ πŸ”΄
Environment Type Account Types 🟒 🟒 🟒 n/a 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Environment Type Resource Types 🟒 🟒 🟒 n/a 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Default Org (define mangemnt env) 🟒 n/a n/a n/a 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Default Org (define backup env) 🟒 n/a n/a n/a 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Resource type Dependencies 🟒 🟒 🟒 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Bootstrap / Account Role Resource Confit 🟒 🟒 🟒 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Configure Organization Types Actions

Feature Tested Code Review Security Review
Management Environment - Type ID 🟒 πŸ”΄ πŸ”΄
Backup Environment - Type ID 🟒 πŸ”΄ πŸ”΄
View Settings XML 🟒 πŸ”΄ πŸ”΄
Organization Diagram - All 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Enviroments 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Accounts 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Per org/env resources 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Type descriptions 🟒 πŸ”΄ πŸ”΄
Actions File (menus) 🟒 πŸ”΄ πŸ”΄

Configure Organization

  • Multiple enviroments of a single type can be created (Web-Dev, Web-Prod, etc.)
  • Multiple accounts of the same type can be created (Pentest1, Pentest2, etc.)
  • The resource list is pullled from the type configuration, not altered here.
Feature List Add Delete Rename Menus Tested Code Review Security Review
Organization 🟒 🟒 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Evironments 🟒 🟒 🟒 n/a 🟒 🟒 πŸ”΄ πŸ”΄
Environment Accounts 🟒 🟒 🟒 n/a 🟒 🟒 πŸ”΄ πŸ”΄

Configure Organization Actions

Feature Run Tested Code Review Security Review
Create CLI Profiles 🟑 🟑 πŸ”΄ πŸ”΄
Select CLI Profiles 🟒 🟒 πŸ”΄ πŸ”΄
Test CLI Porfile 🟒 🟒 πŸ”΄ πŸ”΄
Look up Org, Root, Acount ID 🟒 🟒 πŸ”΄ πŸ”΄
Organization Seettings 🟒 🟒 πŸ”΄ πŸ”΄
Environment Settings 🟑 🟑 πŸ”΄ πŸ”΄
List Available Account Resources 🟒 🟒 πŸ”΄ πŸ”΄
Organization Diagram - All 🟒 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Enviroments 🟒 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Accounts 🟒 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Per org/env resources 🟒 🟒 πŸ”΄ πŸ”΄
Organization Diagram - Type descriptions 🟒 🟒 πŸ”΄ πŸ”΄
Actions File (menus) 🟒 🟒 πŸ”΄ πŸ”΄

Deploy Actions

Feature Menus Run Tested Code Review Security Review
Select Organization 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deploy Org Resources 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Select Env 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deploy Env Resources 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Select Account 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deploy Account Resources 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deployed Resources Tracking 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deployed Resources Diagram 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deploy With Confirm 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deploy No Prompt 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Drift Actions

Feature Run Tested Code Review Security Review
Drift Report 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Drift Delete Unauthorized Resources πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Drift Deploy Missing Resources πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Deploy Org Resources

Feature Deploy Delete Verify Tested Code Review Security Review
Organization 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Enable All Features 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: env-allowed-regions [env] 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: IMDSV1 [env] 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: always-denied-actions [root] 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: always-default-org-root [root] 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: deploy-scp-require-imdsv2.sh [root] 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Env Resources

Feature Deploy Delete Verify Tested Code Review Security Review
OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: deny-external-access 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP: account specific OU only allowing resources deployed πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
SCP: for different regions than org regions (more restrictive) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Rename OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Account Resources - every account

Feature Deploy Delete Verify Tested Code Review Security Review
Accounts 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Move account to OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Account alias 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Admin roles 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Admin role policy 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delete Default VPC 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Rename account, alias, email, name 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Deny All Environment

Feature Deploy Delete Verify Tested Code Review Security Review
OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Deny All SCP 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Test Environment

Environment where people log into EC2 instances.

OU

Feature Deploy Delete Verify Tested Code Review Security Review
OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
SCP 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Accounts 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Budgets 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Delete Default VPCs 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Admin roles 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
log to security account πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

IAM Account

IAM users in work environment

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
IAM User 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

KMS Account

KMS keys used in enviroment

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS keys 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS policies 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS key aliases 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Network Account

Network resources shared to environmeng via RAM

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
VPC Flow Logs Role 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs VPC 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs Subnet 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs NACL 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Route Table + Routes 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
VPC Endpoints 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Vpc Endoint Security Groups 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs VCP Flow Logs 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs Ram Share 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Work VPC 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Work Subnet 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Work NACL 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Work Route Table + Routes 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Work IGW 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Work Ram Share 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Work VCP Flow Logs 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs Auth VPC 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs Auth Subnet 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs Auth NACL 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs Auth Route Auth Table + Routes 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Jobs AUth IGW 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs Auth VCP Flow Logs 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Jobs Auth Ram Share 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Remote Access Prefix List 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
AWS Services Prefix Lists 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
SSH Security Group 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
RDP Security Group 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
HTTP/HTTPS Security Group 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Account: log to security account πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

AMI Account

Account where people log into EC2 instances.

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Base Ubuntu AMI 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Base Amazon Linux AMI πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Burp AMI 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Collab AMI πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Kiro Dev AMI πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Claude Code Ami πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Codex Ami πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Repos Account

Account where people log into EC2 instances.

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Code Commit Repo 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
ECR πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Work Account

Account where people log into EC2 instances.

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
IPAM pool 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
IPAM EIP allocation 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
S3 buckets (with KMS) 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Bucket policies 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Kiro Dev ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Kiro Instance Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Kiro Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Burp ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Burp Instance Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Burp Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Collab ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Collab Instance Role πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Collab Instance πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Claude Code Dev ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Claude Code Instance Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Claude Code Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Codex Dev ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Codex Instance Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Codex Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄

Domains Account

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Web Account

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄
Webs 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
log to security account πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Jobs Auth Account

If I use CloudFront have to allow us-east-1 for ACM Cert. Lock down when not acively making chanages.

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Job Auth Lambdas 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Auth Lambda VPC Config 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
ACM Certificate 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
API Gateway 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
API Gateway CNAME 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
DynamoDB 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄

Jobs Run Account

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
S3 buckets 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Job Instance Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Job ENI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Job EC2 Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Job AMI 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Job Run (other resources, lambdas, micro VMs? TBD) 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄

Management Environment

The management environment contains accounts where my organization deletegated administrators exist.

IAM Acount

IAM users in management environment

Feature Deploy Delete Verify Tested Code Review Security Review
Account 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
IAM User 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Org Acount

Feature Deploy Delete Verify Tested Code Review Security Review
Org resource policy 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Kiro Account

IAM users in work environment

Feature Deploy Delete Verify Tested Code Review Security Review
Acoount resources 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Identity Center (requires interaction) 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
Kiro (requires interaction) 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄

IPAM Account (Network)

Feature Deploy Delete Verify Tested Code Review Security Review
Account 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate IPAM admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Firewall Manager admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Network Manager admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate VPC Reachability Analyzer admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
IPAM 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Security Acount

Feature Deploy Delete Verify Tested Code Review Security Review
Account 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Security Hub admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate GuardDuty admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate CloudTrail admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate AWS Config admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Macie admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Inspector admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate IAM Access Analyzer admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Audit Manager admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Health admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Detective admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
S3 Logs buckets (one per env) 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
S3 Logs bucket - with encryption 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure GuardDuty 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure Security Hub 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure CloudTrail 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure AWS Config 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure Macie 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure Inspector 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure IAM Access Analyzer 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Configure Security Alerts 🟑 πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

KMS Acount

Feature Deploy Delete Verify Tested Code Review Security Review
Account, Move to OU, Alias 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS Log Key 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS Log Key Alias 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
KMS Log Key Policy 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Accounting Acount

Feature Deploy Delete Verify Tested Code Review Security Review
Account, Move to OU, Alias 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Cost Optimization Hub admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Delegate Compute Optimizer admin 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Org Acount

Feature Deploy Delete Verify Tested Code Review Security Review
Account, Move to OU, Alias 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
Org Policy (org delegated admin) 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄

Jobs

Feature Run Tested Code Review Security Review
Deploy Web Site πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
IAM Acccess Analyzer Report πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Prowler Report πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Enable AWS default Org Role πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Disable AWS default Org Role πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Move website πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Lock Environment (apply deny-all SCP) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Unlock Environment (remove deny-all SCP) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Lock Account (apply deny-all SCP) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Unlock Account (remove deny-all SCP) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Transfer GitHub repo to Code Commit πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Transfer one Code Commit repo to Another πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Troubleshoot Job πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Analyze Network Traffic πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Analyze System Logs πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Move Domain πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Move Hosted Zone πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Register domain πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Update Parent Hosted Zone (specific steps TBD) πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Share all amis to all acounts in ou πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Share AMI To External πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄
Archive Acount πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Backup Environment

Env OU

Back up infrastructure segregated from other infrastructure

Feature Deploy Delete Verify Tested Code Review Security Review
Backup OU 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
budgets 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
delete default vpcs 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄
admin roles 🟒 🟒 🟒 🟒 πŸ”΄ πŸ”΄
log to security account πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Backup Admin Account

Feature Deploy Delete Verify Tested Code Review Security Review
Delegate Backup admin 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄

KMS Account

Feature Deploy Delete Verify Tested Code Review Security Review
Delegate Backup admin 🟑 🟑 🟑 🟑 πŸ”΄ πŸ”΄

Backup Accounts

Feature Deploy Delete Verify Tested Code Review Security Review
Backup Account Per Environment πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄ πŸ”΄

Single Account Test Environment

Single Account Resources To Run Jobs (?)

Deploy environment to single account (account in a different organization or standalone)

Feature Deploy Delete Verify Tested Code Review Security Review
Network 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
User 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Role 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄
Jobs Instance 🟑 🟑 🟑 πŸ”΄ πŸ”΄ πŸ”΄

About

Tracking how long it takes to write code and how much it costs

Resources

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors