Read-only Tier-2 idle/anomalous-spend + idle-resource posture checker for the R720 agent-team (design D5 / §4 / §6.3 / §7 Phase 3). Mirrors the Tier-1 checker conventions verbatim (flags --canary/--dry-run/--no-api/--targets, mode-600 report under $REPORT_ROOT/aws-posture/<date>/, ALARM-only, finding.schema.json spirit, exit 0/2/3, shared substrate redact/post_slack_alarm). Detectors (complement GuardDuty/SecurityHub/Config, do not replace): - anomalous Cost Explorer deltas (ce get-anomalies, $-impact threshold) - stopped EC2 still paying for attached EBS - unattached EBS volumes - unassociated Elastic IPs - idle NAT gateways (≈0 bytes out) - idle load balancers (0 healthy targets) - idle RDS (0 connections over window) Live AWS calls are PROVISIONING-GATED: they run ONLY when Roles Anywhere creds are available (STS identity probe) AND not --no-api/--canary. With no creds or --no-api/--canary the checker SKIPS live calls and notes them — NEVER alarms on missing data (memory feedback_cloudwatch_alarms). Roles Anywhere/step-ca are not stood up (IAM cross-review PASSED 2026-06-18; see security-review/iam/). Offline canary: fixtures of mocked AWS responses (cost/describe-* JSON) under fixtures/aws-posture/ + EXPECTED_FINDING_COUNT=7, asserted fully offline (no aws, no network). Identical detector code runs online and offline. shellcheck-clean (only accepted SC1091), chmod +x. |
||
|---|---|---|
| .. | ||
| fixtures | ||
| aws-posture.sh | ||
| compliance-drift.sh | ||
| confluence-doc.sh | ||
| dependency-cve.sh | ||
| doc-drift.sh | ||
| plan-groomer.sh | ||