Category: AWS Examples
Practical AWS SDK for JavaScript v3 scripts for costs, S3, IAM, EC2, Lambda, Route 53 and CloudFront.
-
Enable DynamoDB Point-in-Time Recovery on Every Table
A TypeScript script that reports PITR status, size and estimated cost for every DynamoDB table and turns PITR on only when you pass –apply.
-
Find CloudWatch Alarms Stuck in INSUFFICIENT_DATA
A TypeScript AWS SDK v3 script that lists CloudWatch alarms stuck in INSUFFICIENT_DATA, checks whether their metrics still exist, and deletes only with –apply.
-
Find Unused Route 53 Hosted Zones
A read-only TypeScript AWS SDK v3 script that flags Route 53 hosted zones with no records, no delegation or no queries, and what they…
-
Find Expiring ACM Certificates Before They Break HTTPS
A read-only TypeScript AWS SDK v3 script that lists ACM certificates expiring soon, explains which won’t auto-renew, and checks their validation CNAMEs.
-
Find Public Lambda Function URLs (AuthType NONE)
A read-only TypeScript AWS SDK v3 script that lists every Lambda function URL, flags AuthType NONE with a public resource policy, and shows CORS…
-
Find EC2 Instances Without IMDSv2 and Require It
A TypeScript AWS SDK v3 script that lists EC2 instances still accepting IMDSv1, counts their IMDSv1 calls, and requires IMDSv2 only when you pass…
-
Delete Old ECR Images With a Lifecycle Policy
A TypeScript AWS SDK v3 script that finds ECR repositories with no lifecycle policy, estimates what old images cost, and sets a policy only…
-
Find Unused IAM Roles With RoleLastUsed
A report-only TypeScript script that lists IAM roles unused for 90 days, with last-used date, Region and who the role trusts.
-
Find Public EBS and RDS Snapshots
A TypeScript script that finds EBS, RDS and Aurora snapshots shared with every AWS account and removes public access only with –apply.
-
Find Unencrypted EBS Volumes and Turn On Default Encryption
A TypeScript script that lists unencrypted EBS volumes per Region and turns on EBS encryption by default only when you pass –apply.