AwsCLI icon
Script icon
Process icon
If icon
SlackIncomingWebhook icon
Log icon
Schedule icon
Webhook icon

AWS IAM Credential Hygiene Audit with Kestra

Audit AWS IAM credentials in Kestra. Flag keys past rotation, never-used credentials, and missing MFA from the credential report, then alert Slack weekly.

Categories
Cloud

Every security checklist says rotate access keys every 90 days. Almost no account does, because nothing fails when a key turns two years old, and the person who created it left the company in March. The AWS credential report already contains the evidence - key ages, last-used timestamps, MFA state - but it is a CSV you have to remember to download. This blueprint runs the report on a cadence and turns each hygiene violation into a named finding in the team channel.

How it works

  1. generate_report (io.kestra.plugin.aws.cli.AwsCLI) calls iam generate-credential-report - AWS builds the report asynchronously, so it is a separate step from reading it.
  2. fetch_report (same plugin) pulls iam get-credential-report --query Content --output text, leaving the base64-encoded CSV in stdOut, with credentials from {{ secret('AWS_ACCESS_KEY_ID') }} / {{ secret('AWS_SECRET_ACCESS_KEY') }}.
  3. analyze_credentials (io.kestra.plugin.scripts.python.Script on the Process runner, stdlib only) decodes the CSV and applies four rules per user: active key older than max_key_age_days (stale_key), active key never used or idle past max_unused_days (unused_key), console password unchanged past the same age (stale_password), and password enabled without MFA when require_mfa is on (missing_mfa). Findings are capped at 25 for the alert, with the full count always reported.
  4. credential_gate (io.kestra.plugin.core.flow.If) posts the per-user findings to Slack; a clean account logs a one-line all-clear.
  5. The flow-level errors handler alerts Slack when the audit itself breaks - a missing IAM permission must never read as a clean account.

What you get

  • Every overdue key, idle credential, and MFA gap as a named, actionable line.
  • Thresholds as inputs, so your rotation policy is the configuration, not a code edit.
  • finding_count, scanned_users, and the findings list as outputs for tracking hygiene over time.
  • A weekly cadence plus a webhook for the moment after an offboarding.

Who it's for

  • Security and platform teams running CIS AWS Foundations-style benchmarks who want the credential section automated.
  • Companies with employee turnover where key ownership outlives employment.
  • Anyone who has seen Access key ... active ... last used: N/A in a quarterly review.

Why orchestrate this with Kestra

The credential report is a manual export: someone logs in, downloads, greps, and emails. Skip one quarter and the rotation policy is fiction. Kestra schedules the audit, retries transient API failures, alerts when the audit itself cannot run (the failure that matters most for a security control), keeps execution history as evidence for auditors, and exposes the findings as outputs the next workflow can act on - a Jira ticket task is three lines away.

Prerequisites

  • IAM permissions iam:GenerateCredentialReport and iam:GetCredentialReport on the credentials running the flow.
  • A Kestra instance with outbound access to the AWS IAM API (global endpoint).

Secrets

  • AWS_ACCESS_KEY_ID: AWS key with IAM credential report read access.
  • AWS_SECRET_ACCESS_KEY: matching AWS secret.
  • SLACK_WEBHOOK_URL: Slack incoming webhook URL for findings and failure alerts.

Quick start

  1. Add the three secrets above to your Kestra instance.
  2. Adjust max_key_age_days, max_unused_days, and require_mfa to your policy.
  3. Run once manually and read the analyze_credentials outputs before enabling the schedule.
  4. Enable the weekly schedule, or wire the on_demand webhook into your offboarding runbook.

How to extend

  • Open a GitHub issue from the same findings with github.issues.Create, so each violation lands in the backlog with an owner.
  • Split the then branch with a Switch on f.kind so missing MFA reaches a different channel than stale keys.
  • Load findings into a table to chart credential hygiene over quarters for audit evidence.
  • Add cert_1_active / cert_2_active checks for accounts still using signing certificates.

Links

See How

New to Kestra?

Use blueprints to kickstart your first workflows.