Category: AWS Examples
Practical AWS SDK for JavaScript v3 scripts for costs, S3, IAM, EC2, Lambda, Route 53 and CloudFront.
-
Find SQS Queues Without a Dead-Letter Queue
A read-only TypeScript script that lists SQS queues with no dead-letter queue, broken redrive targets, risky maxReceiveCount values and DLQ depth.
-
Find Lambda Functions With Too Much Memory
A report-only AWS SDK v3 script that compares each Lambda function’s peak memory with its setting and estimates what right-sizing would save.
-
Find Untagged AWS Resources With the Tagging API
A read-only TypeScript script that lists AWS resources missing your required tag keys, per Region, and writes the result to CSV for owners to…
-
Find Unused VPC Interface Endpoints
A read-only TypeScript AWS SDK v3 script that flags interface and Gateway Load Balancer endpoints with no traffic and estimates what each costs per…
-
Find Unattached Elastic Network Interfaces (ENIs)
A TypeScript AWS SDK v3 script that lists ENIs in the available state, separates service-managed ones, and deletes yours only when you pass –apply.
-
Find Load Balancers Serving Plain HTTP Without a Redirect
A read-only TypeScript AWS SDK v3 script that flags ALB HTTP listeners serving plain HTTP and HTTPS listeners whose security policy still allows TLS…
-
Check GuardDuty Is Enabled in Every AWS Region
A TypeScript AWS SDK v3 script that reports GuardDuty detectors and features per Region, and creates missing detectors only when you pass –apply.
-

Check CloudTrail Is Enabled and Logging in Every AWS Region
A read-only TypeScript AWS SDK v3 script that shows, Region by Region, whether a CloudTrail trail is logging all management events.
-
Check CloudFront Minimum TLS Version on Every Distribution
A read-only TypeScript report of each CloudFront distribution’s security policy, certificate, viewer protocol policy and origin TLS settings, with findings.
-
Find S3 Buckets Without Lifecycle Rules
A TypeScript script that lists buckets with no lifecycle rules or no multipart cleanup, sized from CloudWatch, and adds a safe cleanup rule only…