v1.0.0-beta.7
Pre-release
Pre-release
What's New
IAM Policy Generation (keep iam)
Keep can now generate a ready-to-use IAM policy JSON based on your actual configuration — no more manually editing example policies from the docs.
# Generate policy scoped to your workspace
keep iam
# Generate for all vaults and environments
keep iam --all
# Generate and open the AWS IAM console
keep iam --browserThe generated policy is tailored to your setup:
- Namespace-scoped — resources and tag conditions use your configured namespace
- Environment-scoped — SSM resource ARNs and Secrets Manager tag conditions are limited to your active environments
- Workspace-aware — respects your personal workspace configuration, so each team member gets a policy matching their access needs
- Multi-vault — combines SSM and Secrets Manager statements into a single policy when both are configured
- KMS-aware — includes the correct KMS key permissions (default or custom)
Improved Onboarding
The first-run experience is significantly smoother:
- Auto-init: Running
keepin an uninitialized directory now launches the setup wizard automatically - Guided flow:
keep initnow walks through vault setup → workspace configuration → IAM policy generation in one seamless flow - AWS SDK detection: Vault drivers check for SDK availability and show clear install instructions if missing
- Credential pre-check: Uses STS
GetCallerIdentitybefore running the full permission matrix, with clear guidance when credentials aren't configured - Better errors: Missing vault configuration now shows actionable suggestions instead of generic errors
Documentation Audit
Comprehensive audit of all 22 documentation pages against source code, fixing 19 inaccuracies including incorrect option names, phantom flags, wrong command names, and an IAM policy tag mismatch that would have caused real policies to fail.
Changelog
- Add
keep iamcommand with workspace-scoped IAM policy generation - Add workspace and IAM policy offers to
keep initsetup flow - Add IAM policy offer to
keep vault:add - Auto-redirect
keepto init when uninitialized - Add
isAvailable()checks on vault drivers for missing AWS SDK - Add AWS credential pre-check via STS before permission matrix
- Show actionable KeepException when no vaults configured
- Fix 19 documentation inaccuracies across 15 files
- Document
keep iamcommand and updated onboarding flow