Skip to content

v1.0.0-beta.7

Pre-release
Pre-release

Choose a tag to compare

@jszobody jszobody released this 22 Mar 23:51
· 3 commits to main since this release

What's New

IAM Policy Generation (keep iam)

Keep can now generate a ready-to-use IAM policy JSON based on your actual configuration — no more manually editing example policies from the docs.

# Generate policy scoped to your workspace
keep iam

# Generate for all vaults and environments
keep iam --all

# Generate and open the AWS IAM console
keep iam --browser

The generated policy is tailored to your setup:

  • Namespace-scoped — resources and tag conditions use your configured namespace
  • Environment-scoped — SSM resource ARNs and Secrets Manager tag conditions are limited to your active environments
  • Workspace-aware — respects your personal workspace configuration, so each team member gets a policy matching their access needs
  • Multi-vault — combines SSM and Secrets Manager statements into a single policy when both are configured
  • KMS-aware — includes the correct KMS key permissions (default or custom)

Improved Onboarding

The first-run experience is significantly smoother:

  • Auto-init: Running keep in an uninitialized directory now launches the setup wizard automatically
  • Guided flow: keep init now walks through vault setup → workspace configuration → IAM policy generation in one seamless flow
  • AWS SDK detection: Vault drivers check for SDK availability and show clear install instructions if missing
  • Credential pre-check: Uses STS GetCallerIdentity before running the full permission matrix, with clear guidance when credentials aren't configured
  • Better errors: Missing vault configuration now shows actionable suggestions instead of generic errors

Documentation Audit

Comprehensive audit of all 22 documentation pages against source code, fixing 19 inaccuracies including incorrect option names, phantom flags, wrong command names, and an IAM policy tag mismatch that would have caused real policies to fail.

Changelog

  • Add keep iam command with workspace-scoped IAM policy generation
  • Add workspace and IAM policy offers to keep init setup flow
  • Add IAM policy offer to keep vault:add
  • Auto-redirect keep to init when uninitialized
  • Add isAvailable() checks on vault drivers for missing AWS SDK
  • Add AWS credential pre-check via STS before permission matrix
  • Show actionable KeepException when no vaults configured
  • Fix 19 documentation inaccuracies across 15 files
  • Document keep iam command and updated onboarding flow