Read-only Tier-2 idle/anomalous-spend + idle-resource posture checker for the R720 agent-team (design D5 / §4 / §6.3 / §7 Phase 3). Mirrors the Tier-1 checker conventions verbatim (flags --canary/--dry-run/--no-api/--targets, mode-600 report under $REPORT_ROOT/aws-posture/<date>/, ALARM-only, finding.schema.json spirit, exit 0/2/3, shared substrate redact/post_slack_alarm). Detectors (complement GuardDuty/SecurityHub/Config, do not replace): - anomalous Cost Explorer deltas (ce get-anomalies, $-impact threshold) - stopped EC2 still paying for attached EBS - unattached EBS volumes - unassociated Elastic IPs - idle NAT gateways (≈0 bytes out) - idle load balancers (0 healthy targets) - idle RDS (0 connections over window) Live AWS calls are PROVISIONING-GATED: they run ONLY when Roles Anywhere creds are available (STS identity probe) AND not --no-api/--canary. With no creds or --no-api/--canary the checker SKIPS live calls and notes them — NEVER alarms on missing data (memory feedback_cloudwatch_alarms). Roles Anywhere/step-ca are not stood up (IAM cross-review PASSED 2026-06-18; see security-review/iam/). Offline canary: fixtures of mocked AWS responses (cost/describe-* JSON) under fixtures/aws-posture/ + EXPECTED_FINDING_COUNT=7, asserted fully offline (no aws, no network). Identical detector code runs online and offline. shellcheck-clean (only accepted SC1091), chmod +x.
27 lines
893 B
JSON
27 lines
893 B
JSON
{
|
|
"Reservations": [
|
|
{
|
|
"Instances": [
|
|
{
|
|
"InstanceId": "i-0aa11bb22cc33dd44",
|
|
"InstanceType": "m5.large",
|
|
"State": { "Name": "stopped" },
|
|
"StateTransitionReason": "User initiated (2026-02-01 09:14:00 GMT)",
|
|
"BlockDeviceMappings": [
|
|
{ "DeviceName": "/dev/xvda", "Ebs": { "VolumeId": "vol-stopped-root-001", "Status": "attached" } }
|
|
],
|
|
"Tags": [ { "Key": "Name", "Value": "old-batch-runner" } ]
|
|
},
|
|
{
|
|
"InstanceId": "i-0ff99ee88dd77cc66",
|
|
"InstanceType": "t3.micro",
|
|
"State": { "Name": "running" },
|
|
"BlockDeviceMappings": [
|
|
{ "DeviceName": "/dev/xvda", "Ebs": { "VolumeId": "vol-running-root-002", "Status": "attached" } }
|
|
],
|
|
"Tags": [ { "Key": "Name", "Value": "active-web" } ]
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|