Category: AWS Examples
Practical AWS SDK for JavaScript v3 scripts for costs, S3, IAM, EC2, Lambda, Route 53 and CloudFront.
-
Find Plaintext Secrets in ECS Task Definitions
A TypeScript AWS SDK v3 script that finds plaintext passwords and keys in ECS container environment variables and maps secret references to execution roles.
-
Find Secrets in Lambda Environment Variables
A TypeScript AWS SDK v3 script that finds access keys, tokens and passwords in Lambda environment variables without ever printing a secret value.
-
Create an AWS Budget Alert With AWS SDK v3
A dry-run-first TypeScript script that creates a monthly AWS cost budget with actual and forecasted alerts, and only adds what’s missing when you run…
-
Find Orphaned EBS Snapshots Whose Volume Is Gone
A report-first AWS SDK v3 script that finds EBS snapshots whose volume no longer exists and no AMI needs, prices them, and archives or…
-
Find Previous-Generation EC2 Instances to Upgrade
A read-only TypeScript script that lists EC2 instances on previous-generation types, suggests same-size current types and compares their hourly prices.
-

Find EC2 Instances Not Managed by Systems Manager
A read-only TypeScript AWS SDK v3 script that lists running EC2 instances Systems Manager can’t reach, with the likely cause for each one.
-
Check AWS Config Is Recording in Every Region
A read-only TypeScript AWS SDK v3 script that shows, Region by Region, whether AWS Config is recording, what it records and whether delivery works.
-
Find IAM Policies That Grant Admin Access
A read-only TypeScript AWS SDK v3 script that finds managed and inline IAM policies granting admin or near-admin access, and who has AdministratorAccess.
-
Find RDS Instances Without Automated Backups or Encryption
A TypeScript AWS SDK v3 script that reports RDS instances and clusters with no automated backups, unencrypted storage or deletion protection off.
-
Find Publicly Accessible RDS Instances
A TypeScript AWS SDK v3 script that finds RDS and Aurora instances reachable from the internet, and turns off public access only with –apply.