leaveaws.com

Every AWS service, and how to leave it.

Pick the service you're stuck on. Each row lists real alternatives and a copy-paste prompt you can hand to Claude, ChatGPT, Cursor or any agent with your AWS credentials to inventory what you have and plan the move.

Grows over time. Not affiliated with Amazon. Suggest a service or alternative.

Leaving for good? Don't pay egress β€” AWS waives data-transfer-out fees when you move off.
AWS serviceWhere to go instead

Give the agent read-only keys, not your admin keys

Don't paste credentials that can change or read everything into a terminal. Create a throwaway IAM user with the scoped policy below β€” it can list and describe what you run, but it can't modify anything, read your S3 objects, or fetch your secret values.

  1. Copy the policy JSON below.
  2. AWS Console β†’ IAM β†’ Policies β†’ Create policy β†’ JSON tab β†’ paste β†’ name it leaveaws-inventory-readonly.
  3. IAM β†’ Users β†’ Create user (no console access) β†’ Attach policies directly β†’ pick the policy you just made.
  4. Open the user β†’ Security credentials β†’ Create access key (Command Line Interface) β†’ give that key pair to the agent.
  5. Delete the user when your inventory is done.
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "LeaveAwsInventoryReadOnly",
      "Effect": "Allow",
      "Action": [
        "ec2:Describe*",
        "elasticloadbalancing:Describe*",
        "autoscaling:Describe*",
        "s3:ListAllMyBuckets",
        "s3:ListBucket",
        "s3:GetBucketLocation",
        "s3:GetBucketPolicy",
        "s3:GetBucketVersioning",
        "s3:GetBucketTagging",
        "s3:GetBucketWebsite",
        "s3:GetBucketCORS",
        "s3:GetBucketNotification",
        "s3:GetLifecycleConfiguration",
        "s3:GetEncryptionConfiguration",
        "s3:GetReplicationConfiguration",
        "rds:Describe*",
        "rds:ListTagsForResource",
        "dynamodb:Describe*",
        "dynamodb:List*",
        "lambda:List*",
        "lambda:GetFunctionConfiguration",
        "lambda:GetPolicy",
        "cloudfront:Get*",
        "cloudfront:List*",
        "route53:Get*",
        "route53:List*",
        "route53domains:List*",
        "ses:Get*",
        "ses:List*",
        "sqs:ListQueues",
        "sqs:GetQueueAttributes",
        "sns:Get*",
        "sns:List*",
        "ecs:Describe*",
        "ecs:List*",
        "eks:Describe*",
        "eks:List*",
        "ecr:Describe*",
        "ecr:List*",
        "elasticache:Describe*",
        "cognito-idp:Describe*",
        "cognito-idp:List*",
        "apigateway:GET",
        "secretsmanager:ListSecrets",
        "secretsmanager:DescribeSecret",
        "ssm:DescribeParameters",
        "lightsail:Get*",
        "states:Describe*",
        "states:List*",
        "events:Describe*",
        "events:List*",
        "kafka:Describe*",
        "kafka:List*",
        "es:Describe*",
        "es:List*",
        "bedrock:Get*",
        "bedrock:List*",
        "sagemaker:Describe*",
        "sagemaker:List*",
        "iam:GetRole",
        "iam:ListRoles",
        "iam:ListInstanceProfiles",
        "cloudwatch:GetMetricStatistics",
        "cloudwatch:GetMetricData",
        "cloudwatch:ListMetrics",
        "ce:GetCostAndUsage"
      ],
      "Resource": "*"
    }
  ]
}

Deliberately missing: s3:GetObject, secretsmanager:GetSecretValue, ssm:GetParameter, and every write action. The agent sees names, sizes and configs β€” never your data. When it's time to actually move bytes, do that step with a key scoped to just those buckets, or from a machine you control.

Prompt copied