Abstract
Air IAM is an open-source Blockchain & Cloud Computing project. Least privilege AWS IAM Terraformer. AirIAM scans existing IAM usage patterns and provides a simple method to migrate IAM configurations into a right-sized Terraform plan. It identifies unused users, roles, groups, policies and policy attachments and replaces them with a Least Privileges Terraform code modelled to manage AWS IAM. It is built using Python, AWS, Terraform. Key capabilities include: Detects unused IAM resources using native AWS and Amazon Access Advisor APIs; Provides scripts to remove unused entities en-masse; Effortless migration of existing IAM configurations into a simple Least Privileges Terraform model. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Blockchain & Cloud Computing mini project or final-year project.
1. Introduction
AirIAM scans existing IAM usage patterns and provides a simple method to migrate IAM configurations into a right-sized Terraform plan. It identifies unused users, roles, groups, policies and policy attachments and replaces them with a Least Privileges Terraform code modelled to manage AWS IAM.
AirIAM is battle-tested and is recommended for use in Dev, QA and test environments that have been previously managed by humans. It is design to result in minimal impact on existing workloads.
AirIAM is an AWS IAM to least privilege Terraform execution framework. It compiles AWS IAM usage and leverages that data to create a least-privilege IAM Terraform that replaces the exiting IAM management method.
2. Objective
Least privilege AWS IAM Terraformer
This project demonstrates how Python, AWS, Terraform can be applied to a real-world Blockchain & Cloud Computing problem.
3. Key Features / Modules
- Detects unused IAM resources using native AWS and Amazon Access Advisor APIs.
- Provides scripts to remove unused entities en-masse.
- Effortless migration of existing IAM configurations into a simple Least Privileges Terraform model.
- Integrates with Checkov, a static-code analysis tool for Terraform, to track unwanted configuration changes and configuration drift.
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Python 3.8 or later
- pip / virtualenv for dependencies
- VS Code, PyCharm or Jupyter Notebook
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/bridgecrewio/AirIAM.git
cd AirIAMFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add a CI/CD pipeline with GitHub Actions
- Deploy to a public test network or cloud free tier
- Add monitoring and cost alerts
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Why does this problem need a blockchain or cloud-native design?
- Explain the smart contract / infrastructure components and how they interact.
- How are gas costs or cloud costs kept under control?
- How is the system secured (keys, IAM, access control)?
- How would the solution scale to many more users?
9. Source Code & License
This project is developed by bridgecrewio and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Blockchain & Cloud Computing project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Blockchain & Cloud Computing Internship