Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -330,6 +330,7 @@ Context ordering:
| S3 | S3 Browser |
| Lambda | Lambda Browser |
| DynamoDB | Table Browser & Key Lookup |
| AWS Backup | Recovery Browser |
| WAF | WAFv2 Web ACL Browser |
| Bedrock | API Key Manager |
| IAM | IAM User Browser |
Expand Down Expand Up @@ -471,6 +472,7 @@ checks:
| Step Functions | `/` filter state machines by name/ARN/type/region or executions by status/name/ARN, `r` refresh, `Enter` executions/detail, detail `↑`/`↓` scroll, `PgUp`/`PgDn` page |
| Lambda | `A` toggle all-regions scope (multi-region contexts), `Enter` invoke, `d` detail, `l` view CloudWatch Logs, `/` filter, `r` refresh |
| DynamoDB | `/` filter, `r` refresh, `Enter` table detail, detail `l` prompts for the complete partition/sort key and performs one `GetItem`, `↑`/`↓` and `PgUp`/`PgDn` scroll details or item JSON |
| AWS Backup | `/` filter vaults, `r` refresh, `Enter` recovery-readiness detail, detail `↑`/`↓` scroll and `PgUp`/`PgDn` page through recovery points, protected resources, and recent failed/expired jobs |
| WAFv2 | `/` filter, `r` refresh regional and CloudFront scopes, `Enter` logging/association/rule detail, detail `↑`/`↓` scroll, `PgUp`/`PgDn` page |

The command palette (`P`) fuzzy-searches three kinds of items from anywhere outside text-entry screens: service features (jump straight into a browser), contexts (switch without opening the picker), and resources indexed across services. Opening the palette starts an async index of EC2 instances, RDS instances, Lambda functions, S3 buckets, ECS clusters, and Route53 zones in the current context. Press `Tab` to opt into searching the active context plus sync-managed contexts; context fan-out is bounded, rows show context and region tags, and per-context/service failures are shown inline. Matching covers names, IDs, ARNs, contexts, and regions where available. Selecting a resource in another context switches context and then jumps to the owning browser with the shared filter prefilled to that resource.
Expand Down Expand Up @@ -510,6 +512,8 @@ The DynamoDB Table Browser lists billing mode, provisioned capacity or on-demand

The WAFv2 Web ACL Browser combines regional ACLs from the active region with global ACLs queried through the required `us-east-1` endpoint. Rows surface default action, WCU capacity, managed/total rule counts, logging state, protected-resource counts, and informational flags for logging disabled, permissive default actions, and unassociated ACLs. Detail shows priority-ordered rules, actions/overrides, visibility settings, log destinations, regional associations, Amplify associations, CloudFront distributions, and CloudFront distribution tenants. Regional and CloudFront failures, plus individual detail, logging, and association failures, remain isolated so successful results stay visible. The active identity needs `wafv2:ListWebACLs`, `wafv2:GetWebACL`, `wafv2:GetLoggingConfiguration`, `wafv2:ListResourcesForWebACL`, `cloudfront:ListDistributionsByWebACLId`, and `cloudfront:ListDistributionTenantsByCustomization`; some protected resource types require additional service-specific list permissions.

The AWS Backup Recovery Browser lists vault state, type, recovery-point count, encryption key, and Vault Lock retention metadata in the active region. Opening a vault shows failure/expiry-prioritized recovery points, protected resources with their latest backup, and failed, expired, aborted, partial, or completed-with-issues jobs from AWS Backup's recent job window. Each paginated section is independent: completed pages and other sections remain visible when a later page or one section is denied, with the failure summarized inline. The browser is read-only and requires `backup:ListBackupVaults`, `backup:ListRecoveryPointsByBackupVault`, `backup:ListProtectedResourcesByBackupVault`, and `backup:ListBackupJobs`.

The CloudTrail Event Lookup answers "who changed what, and when": recent API events list newest-first with mutations marked `*`, actor, call, and source service per row. Keys `1`-`5` switch the time window (1h/6h/24h/3d/7d), `m` restricts to mutations (server-side via the `ReadOnly=false` lookup attribute), and `n` runs a server-side resource-name lookup — CloudTrail accepts one lookup attribute per call, so combining both applies the mutations restriction client-side. Results are capped at 100 events per query, so narrow the window or use the resource lookup when a busy account truncates. Event detail shows actor, source, region, source IP, touched resources, and the full raw event JSON with scrolling.

The CloudWatch Alarm Browser is an alarm-first incident entry point: alarms list firing-first (ALARM, then INSUFFICIENT_DATA, then OK) with a `tab`-cycled state filter and text filtering across names, states, metrics, and dimensions. Alarm detail shows the state reason, condition, dimensions, and the most recent state transitions. When an alarm's dimensions map to a supported browser (`DBInstanceIdentifier`, `InstanceId`, `ClusterName`, `FunctionName`, `LoadBalancer`, `TargetGroup`), `g` jumps into that resource browser with the filter prefilled to the unhealthy resource (for ELB alarms the target group filter is prefilled too, so the drill-down lands on the alarmed target group), and `l` opens CloudWatch Logs prefilled with the derived log group (e.g. `/aws/lambda/<function>`).
Expand Down
2 changes: 2 additions & 0 deletions docs/architecture.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@ Current repository clients include:
- KMS
- DynamoDB
- WAFv2 (regional and `us-east-1` CloudFront-scope clients, plus distribution and distribution-tenant association lookups)
- AWS Backup

Pattern:

Expand Down Expand Up @@ -268,6 +269,7 @@ Current screen families include:
- EventBridge rule list/detail, scrollable complete event patterns, and type-to-confirm state changes for eligible rule modes
- DynamoDB table list/detail and complete-primary-key `GetItem` flows
- WAFv2 regional/CloudFront Web ACL list and scrollable posture/rule detail flows
- AWS Backup vault list and scrollable recovery-point/protected-resource/failed-job detail flows
- Inspector mode home, checklist setup, security findings/detail (including KMS rotation findings), and checklist results/detail flows
- context picker, context add, and TUI-native context setup/export/unset flows
- SSO account / role selection and exit notice flows
Expand Down
2 changes: 2 additions & 0 deletions docs/architecture.ko.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@ repository와 서비스별 AWS 연동 계층이다.
- KMS
- DynamoDB
- WAFv2 (regional 및 `us-east-1` CloudFront scope client와 distribution 및 distribution tenant association lookup)
- AWS Backup

패턴:

Expand Down Expand Up @@ -268,6 +269,7 @@ UNIC은 현재 다섯 가지 인증 모드를 지원한다.
- EventBridge rule list/detail, 스크롤 가능한 전체 event pattern, 변경 가능한 rule mode의 type-to-confirm 상태 변경 flow
- DynamoDB table list/detail, 전체 primary key 기반 `GetItem`
- WAFv2 regional/CloudFront Web ACL list, 스크롤 가능한 posture/rule detail
- AWS Backup vault list, recovery point/protected resource/failed job 스크롤 상세 화면
- Inspector mode home, checklist setup, KMS rotation finding을 포함한 security findings/detail, checklist results/detail
- context picker, context add, TUI-native context setup/export/unset
- SSO account / role selection, exit notice
Expand Down
1 change: 1 addition & 0 deletions docs/project-overview.en.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ Implemented service areas currently include:
The application already includes interactive mutation flows, polling-based status flows, context helpers, and per-service drill-down screens. EC2 includes a first-class Auto Scaling Group browser for capacity, instance health, recent activity failures, and type-confirmed desired-capacity changes. CloudFormation includes failure-prioritized stack browsing, parameters, outputs, recent events with failure reasons, and polling-based drift detection. CloudWatch Metrics now includes resource-centric preset groups plus time-range, period, and statistic controls for faster terminal triage. EKS includes managed add-on status review, current-version upgrade readiness checks that compare control plane, managed node group, managed add-on version alignment, and EKS upgrade insights before a target upgrade is planned, plus a kubeconfig access helper that prepares copyable `aws eks update-kubeconfig` and `kubectl` handoff commands. ECR includes repository and image/tag browsing with cleanup-oriented untagged and stale image signals. FIS includes experiment template browsing with safe-run blast-radius preview, targets, actions, role ARN, stop condition summaries, and recent experiment history with status, timing, and failure/stop reasons. ACM includes an expiry-sorted certificate browser with validation, renewal, domain, and in-use details. KMS includes key browsing with aliases, state, manager, and automatic-rotation posture. Both browsers keep successfully loaded resources visible when an individual detail lookup fails and surface the failure inline; denied KMS rotation lookups are shown as unknown. ElastiCache includes replication-group and standalone-cluster browsing with node metadata and copyable endpoints. Step Functions includes state machine browsing and failure-first STANDARD execution triage with failed-state, error/cause, and input/output previews. EventBridge includes cross-bus rule browsing with complete scrollable event patterns, targets, best-effort seven-day CloudWatch trigger activity, and type-to-confirm enable/disable actions for eligible customer-managed rules; all-management-events rules remain read-only so their exact matching mode is preserved. SNS includes name-sorted topic browsing with subscription counts, encryption, and delivery policies, plus a pending-first subscription list; topics whose attribute lookup is denied stay listed with their attributes marked unavailable. DynamoDB includes table capacity, size, key, GSI, TTL, and stream inspection plus a single `GetItem` lookup by complete primary key; it has no scan path.
WAF combines regional and CloudFront-scope Web ACL posture, priority-ordered rules, logging, and supported resource associations while keeping scope and per-resource authorization failures isolated.
API Gateway v2 includes HTTP/WebSocket API, stage, route, and integration browsing with partial-detail warnings, copyable targets, and filtered Lambda handoff.
AWS Backup includes read-only vault browsing with recovery points, protected resources, Vault Lock/encryption metadata, and recent failed or expired jobs; paginated partial results remain visible with inline warnings.
Inspector mode now includes built-in security and cost/waste scans, including customer-managed KMS key rotation checks and ACM certificate expiry findings, plus checklist-driven readiness checks for RDS, security groups, secrets, Route53, VPCs/subnets, CloudWatch Logs, and baseline posture wrappers. The cost/waste pack surfaces unattached EIPs and EBS volumes, stopped EC2 instances, empty target groups, untagged EC2-family resources, and EBS snapshots aged 90 days or more. Per-resource lookup failures appear as warnings while findings from successful lookups remain available. When `inspector.required_tags` is configured, it additionally reports missing required keys on Elastic IPs, EBS volumes and snapshots, and EC2 instances.

## Primary User Flows
Expand Down
1 change: 1 addition & 0 deletions docs/project-overview.ko.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ UNIC은 다음 세 가지를 결합한 Go 기반 AWS 터미널 콘솔이다.
애플리케이션은 이미 상호작용형 변경 작업 플로우, polling 기반 상태 확인, context helper, 서비스별 drill-down 화면을 포함한다. EC2에는 capacity, instance health, 최근 activity failure를 확인하고 type-to-confirm으로 desired capacity를 변경하는 Auto Scaling Group browser가 포함된다. CloudFormation은 실패/rollback 상태를 우선한 stack 목록, parameter, output, 실패 원인을 포함한 최근 event, polling 기반 drift detection을 제공한다. CloudWatch Metrics는 이제 resource-centric preset 그룹과 time-range / period / statistic control을 제공해 터미널에서 더 빠르게 triage할 수 있다. EKS는 cluster 화면에서 managed add-on 상태를 확인하고, target upgrade를 계획하기 전에 control plane, managed node group, managed add-on의 current-version alignment와 EKS upgrade insight를 함께 확인하는 upgrade readiness check와 복사 가능한 `aws eks update-kubeconfig` / `kubectl` handoff 명령을 준비하는 kubeconfig access helper를 포함한다. ECR은 repository와 image/tag 탐색을 제공하고, untagged image와 오래된 image를 cleanup 후보로 드러낸다. FIS는 experiment template 목록과 safe-run blast-radius preview, target, action, role ARN, stop condition 요약 상세 화면에 더해 최근 experiment history의 상태, 시간, failure/stop reason을 보여준다. ACM은 만료일 순서의 인증서 목록과 validation, renewal, domain, 사용 리소스 상세 정보를 제공한다. KMS는 alias, 상태, 관리 주체, 자동 rotation 상태를 포함한 key 탐색을 제공한다. 두 browser 모두 개별 detail lookup이 실패해도 성공적으로 불러온 resource를 유지하고 실패 내용을 inline으로 표시하며, 권한이 거부된 KMS rotation lookup은 unknown으로 표시한다. ElastiCache는 replication group과 standalone cluster 탐색, node metadata, endpoint 복사를 제공한다. Step Functions는 state machine 탐색과 실패 우선 STANDARD execution triage를 제공하며 failed state, error/cause, input/output preview를 보여준다. EventBridge는 전체 event bus의 rule과 스크롤 가능한 전체 event pattern, target, 최근 7일 CloudWatch 기반 best-effort trigger activity를 보여주고 변경 가능한 customer-managed rule의 enable/disable을 type-to-confirm으로 보호한다. all-management-events rule은 정확한 matching mode를 보존하기 위해 read-only로 유지한다. SNS는 이름순 topic 탐색과 subscription 수, 암호화, delivery policy를 보여주고 pending 우선 subscription 목록을 제공하며, attribute 조회가 거부된 topic도 attribute를 unavailable로 표시한 채 목록에 남긴다. DynamoDB는 table capacity, size, key, GSI, TTL, stream 정보를 보여주고 전체 primary key를 입력받아 단일 `GetItem`만 수행하며 scan 경로는 제공하지 않는다.
WAF는 regional 및 CloudFront scope Web ACL의 posture, priority 순서의 rule, logging, 지원되는 resource association을 함께 보여주며 scope 또는 개별 resource 권한 오류가 다른 결과를 숨기지 않도록 격리한다.
API Gateway v2는 부분 detail 실패 warning, target 복사, filter가 적용된 Lambda handoff를 포함해 HTTP/WebSocket API, stage, route, integration 탐색을 제공한다.
AWS Backup은 recovery point, protected resource, Vault Lock/encryption metadata, 최근 실패 또는 만료 job을 확인하는 read-only vault browser를 제공하며, pagination 일부가 실패해도 성공한 결과를 inline warning과 함께 유지한다.
Inspector mode는 이제 customer-managed KMS key rotation 검사와 ACM 인증서 만료 finding을 포함한 built-in security 및 cost/waste scan과 함께 RDS, security group, secret, Route53, VPC/subnet, CloudWatch Logs, baseline posture wrapper를 다루는 checklist 기반 readiness check도 포함한다. cost/waste rule pack은 연결되지 않은 EIP와 EBS volume, 중지된 EC2 instance, 비어 있는 target group, 사용자 정의 tag가 없는 EC2 계열 resource, 90일 이상 된 EBS snapshot을 표시한다. 개별 resource lookup 실패는 warning으로 표시되며 성공한 lookup의 finding은 그대로 유지된다. `inspector.required_tags`가 설정되면 Elastic IP, EBS volume과 snapshot, EC2 instance에서 누락된 필수 tag key도 추가로 표시한다.

## 주요 사용자 흐름
Expand Down
1 change: 1 addition & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require (
github.com/aws/aws-sdk-go-v2/service/acm v1.44.1
github.com/aws/aws-sdk-go-v2/service/apigatewayv2 v1.37.7
github.com/aws/aws-sdk-go-v2/service/autoscaling v1.61.1
github.com/aws/aws-sdk-go-v2/service/backup v1.60.2
github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.3
github.com/aws/aws-sdk-go-v2/service/cloudfront v1.68.0
github.com/aws/aws-sdk-go-v2/service/cloudtrail v1.55.9
Expand Down
2 changes: 2 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,8 @@ github.com/aws/aws-sdk-go-v2/service/apigatewayv2 v1.37.7 h1:E/fv46bTpl5E9V52ju9
github.com/aws/aws-sdk-go-v2/service/apigatewayv2 v1.37.7/go.mod h1:YNiiAniVgPBIoa9cAFsHR/xscIdpbj57yu7gPYUkwdY=
github.com/aws/aws-sdk-go-v2/service/autoscaling v1.61.1 h1:VB+9RFYfUUY8TyL6W025CZToo6h9vC3zeYob7M7/2CE=
github.com/aws/aws-sdk-go-v2/service/autoscaling v1.61.1/go.mod h1:6q/I1pH386VpPfB6FE62X/MOs6NW/oCsY9FXU33YXOU=
github.com/aws/aws-sdk-go-v2/service/backup v1.60.2 h1:b3QwmC6vV20LLbUGedok6UlOe45HgnW7C93MThgk0P4=
github.com/aws/aws-sdk-go-v2/service/backup v1.60.2/go.mod h1:zMHhtRP9145uUJxHZM7yURy5/d/mn837hyVWBSz5RaM=
github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.3 h1:FjNSXIPC9bbvVRh67j7jGf37gJo/5THzf+pS3T+Don0=
github.com/aws/aws-sdk-go-v2/service/cloudformation v1.76.3/go.mod h1:yQcvrM5JfBihExrlz+2k7W6mBEM6xexhWT8eHr0akzs=
github.com/aws/aws-sdk-go-v2/service/cloudfront v1.68.0 h1:JEXUV287ovPx1ttxFSO2O7Cy4IqkB5EJhmDz+wir1pI=
Expand Down
6 changes: 6 additions & 0 deletions internal/app/app.go
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,8 @@ const (
screenDynamoDBTableDetail
screenDynamoDBLookupInput
screenDynamoDBLookupResult
screenBackupVaultList
screenBackupVaultDetail
screenWAFWebACLList
screenWAFWebACLDetail
screenBedrockKeyList
Expand Down Expand Up @@ -230,6 +232,7 @@ type Model struct {
eventBridge eventBridgeModel
lambda lambdaModel
dynamodb dynamoDBModel
backup backupModel
waf wafModel
inspector inspectorModel

Expand Down Expand Up @@ -365,6 +368,7 @@ func New(cfg *config.Config, configPath string, version string, checklistPath ..
model.apiGatewayV2 = newAPIGatewayV2Model()
model.lambda = newLambdaModel()
model.dynamodb = newDynamoDBModel()
model.backup = newBackupModel()
model.waf = newWAFModel()
model.inspector = newInspectorModel(configuredChecklistPath)
model.applyServiceListFilter()
Expand Down Expand Up @@ -984,6 +988,8 @@ func (m Model) startFeature(kind domain.FeatureKind) (tea.Model, tea.Cmd) {
return m.lambda.Start(&m)
case domain.FeatureDynamoDBBrowser:
return m.dynamodb.Start(&m)
case domain.FeatureBackupBrowser:
return m.backup.Start(&m)
case domain.FeatureWAFWebACLBrowser:
return m.waf.Start(&m)
case domain.FeatureBedrockAPIKeys:
Expand Down
1 change: 1 addition & 0 deletions internal/app/context_terminal.go
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,7 @@ func (m Model) selectedContextInfo() (config.ContextInfo, bool) {
}

func (m Model) beginContextSetup(selected config.ContextInfo) (tea.Model, tea.Cmd) {
normalizeBackupContextReturn(&m)
if pendingAPIGatewayV2ContextLoad(&m) {
normalizeAPIGatewayV2ContextReturns(&m)
}
Expand Down
2 changes: 1 addition & 1 deletion internal/app/feature_submodel.go
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ type featureSubmodel interface {
// such as service selection, context selection, SSM session launch, loading, and
// errors remain root-owned unless a separate shell abstraction is introduced.
func (m *Model) featureSubmodels() []featureSubmodel {
return []featureSubmodel{&m.ec2Browser, &m.autoScaling, &m.ecs, &m.eks, &m.ecr, &m.fis, &m.vpc, &m.reachability, &m.cwMetrics, &m.cwAlarms, &m.cloudTrail, &m.cwLogs, &m.rds, &m.cloudFormation, &m.route53, &m.iam, &m.bedrock, &m.secrets, &m.security, &m.s3, &m.sns, &m.sqs, &m.elb, &m.ssmParams, &m.elasticache, &m.kms, &m.acm, &m.stepFunctions, &m.apiGatewayV2, &m.eventBridge, &m.lambda, &m.dynamodb, &m.waf, &m.inspector}
return []featureSubmodel{&m.ec2Browser, &m.autoScaling, &m.ecs, &m.eks, &m.ecr, &m.fis, &m.vpc, &m.reachability, &m.cwMetrics, &m.cwAlarms, &m.cloudTrail, &m.cwLogs, &m.rds, &m.cloudFormation, &m.route53, &m.iam, &m.bedrock, &m.secrets, &m.security, &m.s3, &m.sns, &m.sqs, &m.elb, &m.ssmParams, &m.elasticache, &m.kms, &m.acm, &m.stepFunctions, &m.apiGatewayV2, &m.eventBridge, &m.lambda, &m.dynamodb, &m.backup, &m.waf, &m.inspector}
}

// overlayPreviousScreen returns the pointer holding the screen a global
Expand Down
1 change: 1 addition & 0 deletions internal/app/filter.go
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,7 @@ const (
filterStepFunctionStateMachines
filterStepFunctionExecutions
filterDynamoDBTables
filterBackupVaults
filterAPIGatewayV2APIs
filterAPIGatewayV2Routes
filterWAFWebACLs
Expand Down
Loading
Loading