kodebeat / papers / cost
Deriving least privilege from what a role actually did
A CloudTrail-to-Terraform IAM policy minimiser.
Compares what an IAM role is allowed to do with what it actually did over an observation window, narrows wildcards to observed actions, and emits a reviewable Terraform snippet. That is the usage-to-pull-request loop IAM never had: a concrete diff, not a report saying the policy is too broad. It is candid about the traps, starting with data events being off by default.
What is in it
- The problem — what goes unanswered without it, and who notices first.
- Why the obvious alternative falls short — stated plainly, including where it is the better choice.
- How it works — the method, not a feature list.
- Concrete use cases — with console output quoted from the repository, never reconstructed.
- The methodology behind any number it emits — every term shown, so the figure survives a question.
- What it deliberately does not do — the section most papers leave out.
Part of the Cost & FinOps theme.
Get the PDF
One email with the download link, and this paper already selected. No follow-up sequence.