Γ
Give the agent read-only keys, not your admin keys
Don't paste credentials that can change or read everything into a terminal. Create a throwaway IAM user with the scoped policy below β it can list and describe what you run, but it can't modify anything, read your S3 objects, or fetch your secret values.
Copy the policy JSON below.
AWS Console β IAM β Policies β Create policy β JSON tab β paste β name it leaveaws-inventory-readonly.
IAM β Users β Create user (no console access) β Attach policies directly β pick the policy you just made.
Open the user β Security credentials β Create access key (Command Line Interface) β give that key pair to the agent.
Delete the user when your inventory is done.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "LeaveAwsInventoryReadOnly",
"Effect": "Allow",
"Action": [
"ec2:Describe*",
"elasticloadbalancing:Describe*",
"autoscaling:Describe*",
"s3:ListAllMyBuckets",
"s3:ListBucket",
"s3:GetBucketLocation",
"s3:GetBucketPolicy",
"s3:GetBucketVersioning",
"s3:GetBucketTagging",
"s3:GetBucketWebsite",
"s3:GetBucketCORS",
"s3:GetBucketNotification",
"s3:GetLifecycleConfiguration",
"s3:GetEncryptionConfiguration",
"s3:GetReplicationConfiguration",
"rds:Describe*",
"rds:ListTagsForResource",
"dynamodb:Describe*",
"dynamodb:List*",
"lambda:List*",
"lambda:GetFunctionConfiguration",
"lambda:GetPolicy",
"cloudfront:Get*",
"cloudfront:List*",
"route53:Get*",
"route53:List*",
"route53domains:List*",
"ses:Get*",
"ses:List*",
"sqs:ListQueues",
"sqs:GetQueueAttributes",
"sns:Get*",
"sns:List*",
"ecs:Describe*",
"ecs:List*",
"eks:Describe*",
"eks:List*",
"ecr:Describe*",
"ecr:List*",
"elasticache:Describe*",
"cognito-idp:Describe*",
"cognito-idp:List*",
"apigateway:GET",
"secretsmanager:ListSecrets",
"secretsmanager:DescribeSecret",
"ssm:DescribeParameters",
"lightsail:Get*",
"states:Describe*",
"states:List*",
"events:Describe*",
"events:List*",
"kafka:Describe*",
"kafka:List*",
"es:Describe*",
"es:List*",
"bedrock:Get*",
"bedrock:List*",
"sagemaker:Describe*",
"sagemaker:List*",
"iam:GetRole",
"iam:ListRoles",
"iam:ListInstanceProfiles",
"cloudwatch:GetMetricStatistics",
"cloudwatch:GetMetricData",
"cloudwatch:ListMetrics",
"ce:GetCostAndUsage"
],
"Resource": "*"
}
]
}
Deliberately missing: s3:GetObject, secretsmanager:GetSecretValue, ssm:GetParameter, and every write action. The agent sees names, sizes and configs β never your data. When it's time to actually move bytes, do that step with a key scoped to just those buckets, or from a machine you control.
Copy policy JSON