v0.3.0
This release makes docket audit something you can run unattended: findings are grouped per table, written to a file or S3, and pushed to an SNS topic.
What's new
- Grouped audit report — repeated deletions of the same table collapse into one block showing every deletion (event name, principal, count, time span, regions) followed by the table's dependents report. The summary line now counts tables deleted with dependents as well as deletions.
docket audit --report PATH— writes the full report to a local path or ans3://bucket/keyuri, including a "none had dependents" report on clean runs.DOCKET_ALERT_TOPIC_ARN— when set, a flagged audit publishes the report to that SNS topic, so an email or chat subscription gets the alert.DOCKET_IGNORE_JOBS— a regex of job and function namesdocket runcatalogs but never sends to the extractor. Defaults to the helper functions the AWS CDK deploys alongside stacks (LogRetention,BucketNotificationsHandler,CustomCDKBucketDeploymen, ...); set it empty to disable.- Catalog age from the source —
check-deleteandauditreport how long ago the catalog was last written where it lives (S3LastModifiedfor remote catalogs) instead of the local cache file's mtime. docket servewithout Steampipe — the web UI opens the catalog as plain sqlite, so it needs no AWS credentials beyond what ans3://DOCKET_DB_PATHrequires and never downloads the extension.
Fixes
- Lambda code download urls are fetched through
GetFunctionsince Steampipe plugin v1.32 stopped including them in thecodecolumn. - A cold
docket runagainst ans3://catalog now creates the cache directory before writing the sqlite file.
Upgrading
No breaking changes. Jobs matching the default DOCKET_IGNORE_JOBS pattern will stop being extracted on the next docket run; set DOCKET_IGNORE_JOBS= (empty) to keep the old behaviour.
Requirements
Python 3.11+, managed with uv.