New to Kestra?
Use blueprints to kickstart your first workflows.
Audit AWS IAM credentials in Kestra. Flag keys past rotation, never-used credentials, and missing MFA from the credential report, then alert Slack weekly.
Every security checklist says rotate access keys every 90 days. Almost no account does, because nothing fails when a key turns two years old, and the person who created it left the company in March. The AWS credential report already contains the evidence - key ages, last-used timestamps, MFA state - but it is a CSV you have to remember to download. This blueprint runs the report on a cadence and turns each hygiene violation into a named finding in the team channel.
generate_report (io.kestra.plugin.aws.cli.AwsCLI) calls iam generate-credential-report - AWS builds the report asynchronously, so it is a separate step from reading it.fetch_report (same plugin) pulls iam get-credential-report --query Content --output text, leaving the base64-encoded CSV in stdOut, with credentials from {{ secret('AWS_ACCESS_KEY_ID') }} / {{ secret('AWS_SECRET_ACCESS_KEY') }}.analyze_credentials (io.kestra.plugin.scripts.python.Script on the Process runner, stdlib only) decodes the CSV and applies four rules per user: active key older than max_key_age_days (stale_key), active key never used or idle past max_unused_days (unused_key), console password unchanged past the same age (stale_password), and password enabled without MFA when require_mfa is on (missing_mfa). Findings are capped at 25 for the alert, with the full count always reported.credential_gate (io.kestra.plugin.core.flow.If) posts the per-user findings to Slack; a clean account logs a one-line all-clear.errors handler alerts Slack when the audit itself breaks - a missing IAM permission must never read as a clean account.finding_count, scanned_users, and the findings list as outputs for tracking hygiene over time.Access key ... active ... last used: N/A in a quarterly review.The credential report is a manual export: someone logs in, downloads, greps, and emails. Skip one quarter and the rotation policy is fiction. Kestra schedules the audit, retries transient API failures, alerts when the audit itself cannot run (the failure that matters most for a security control), keeps execution history as evidence for auditors, and exposes the findings as outputs the next workflow can act on - a Jira ticket task is three lines away.
iam:GenerateCredentialReport and iam:GetCredentialReport on the credentials running the flow.AWS_ACCESS_KEY_ID: AWS key with IAM credential report read access.AWS_SECRET_ACCESS_KEY: matching AWS secret.SLACK_WEBHOOK_URL: Slack incoming webhook URL for findings and failure alerts.max_key_age_days, max_unused_days, and require_mfa to your policy.analyze_credentials outputs before enabling the schedule.weekly schedule, or wire the on_demand webhook into your offboarding runbook.github.issues.Create, so each violation lands in the backlog with an owner.then branch with a Switch on f.kind so missing MFA reaches a different channel than stale keys.findings into a table to chart credential hygiene over quarters for audit evidence.cert_1_active / cert_2_active checks for accounts still using signing certificates.