Skip to content
 
 

Repository files navigation

IAMTrail

AWS Managed Policy Changes Archive

Previously known as MAMIP (Monitor AWS Managed IAM Policies).

Build Status License Website

Track every change to AWS Managed IAM Policies with full version history and validation.

Website | Browse Policies | About


Website

Explore AWS Managed IAM Policies through a searchable web interface at iamtrail.com:

IAMTrail Website

  • A homepage that leads with this week's changes that matter and the newest AWS services spotted, with the charts on /stats
  • Search and filter across 1,465+ managed policies, or search an IAM action to find every policy that grants it, by name or through a wildcard such as s3:Get*
  • Full version history with git diffs for every policy
  • Syntax-highlighted JSON policy viewer, rendered at build time so every policy and IAM action page is readable by search engines and link previews
  • New (v1) policy tracking to spot new AWS services
  • Security findings - a critical, high or medium risk level for every managed policy that grants admin access, a documented pathfinding.cloud privilege escalation path, identity administration, secret or data reads, the power to disable monitoring, or a whole-service wildcard. Each finding says whether the grant is unrestricted or scoped to named resources or a condition, and how to use the policy with caution. Paste aws iam list-attached-role-policies output to check your own role, follow the 90-day timeline of policies that became riskier, or script against /api/v1/risk.json. Access Analyzer security warnings feed the same assessment
  • Known AWS Account lookup - identify who owns one or a whole list of AWS account IDs, powered by the fwdcloudsec/known_aws_accounts community dataset

Get Notified

Subscribe to policy changes:

  • Email Digest (recommended): Subscribe on iamtrail.com - instant, daily or weekly emails with inline diffs, no account required. Paste the output of the command below to follow only the AWS managed policies attached in your account; it is parsed in your browser and only the matched names are stored:

    aws iam list-policies --scope AWS --only-attached --query 'Policies[].Arn' --output text
  • Slack: once your email subscription is confirmed, connect a Slack incoming webhook from the manage page and every notification is also posted to that channel. A webhook Slack revokes is detached automatically and you are emailed.

  • Bluesky (unified feed - IAM policies, endpoints, GuardDuty): @iamtrail.bsky.social

  • RSS Feeds (all feeds):

See docs/notifications-and-social.md for SSM parameters, Bluesky queue, and GitHub Actions IAM.

Browse the Data

All policies are stored as JSON in this repository and updated automatically every hour, every day.

Path Description
policies/ 1,465+ current AWS Managed IAM Policies
findings/ Access Analyzer validation results
DEPRECATED.json Historical record of 73+ deprecated policies

API

The whole archive is also published as versioned JSON at https://iamtrail.com/api/v1. No key, no sign-up, no rate limit - these are static files on the same CloudFront distribution that serves the site. Full documentation at iamtrail.com/api.

Resource Description
/api/v1/index.json Service index: contract version, counts, and the URL of every other resource
/api/v1/policies.json Every tracked policy with its ARN, current version and dates
/api/v1/policies/{policyName}.json One policy: current IAM document plus full version history with per-version action deltas
/api/v1/changes.json Recent changes, each naming the actions added and removed
/api/v1/actions.json Every literal IAM action mapped to the policies that allow, deny or NotAction it, plus wildcardGrants: every Allow wildcard by service prefix and pattern
/api/v1/discoveries.json Actions and service prefixes seen for the first time anywhere in the archive
# What changed in the last day
curl -s https://iamtrail.com/api/v1/changes.json \
  | jq -r '.changes[]
      | select(.date > (now - 86400 | todate))
      | "\(.policyName) \(.versionId): \(.summary)"'

Fields are added, never removed or repurposed, within a version. A breaking change means a new path under /api/v2/.

How It Works

An automated workflow runs every hour, every day:

  1. Fetch all AWS Managed IAM Policies via the AWS API
  2. Detect new, updated, or deprecated policies
  3. Validate each policy with AWS Access Analyzer
  4. Commit changes to git (one commit per policy)
  5. Notify via Bluesky, Telegram, RSS, email digests, subscribers' Slack channels, and an invite-only Discord webhook (SSM only, not linked on the site)

The website also rebuilds daily on its own schedule, so the homepage's seven-day window keeps moving through a week with no policy change.

Credits

Inspired by Scott Piper's original aws_managed_policies repository. Thank you, Scott, for pioneering this.

License

GNU General Public License v3.0 - see LICENSE for details.


Website | RSS Feeds | Bluesky

Made by zoph.io - AWS Cloud Advisory Boutique

Build Status License

Unofficial archive, not affiliated with AWS.

About

Archive of every change to AWS Managed IAM Policies since 2019, with full version history and diffs. Browse it at iamtrail.com.

Topics

Resources

Stars

512 stars

Watchers

20 watching

Forks

Releases

Sponsor this project

Used by

Contributors

Languages