{"id":22671437,"url":"https://github.com/cloudforet-io/plugin-aws-cloud-service-inven-collector","last_synced_at":"2025-09-07T01:33:28.135Z","repository":{"id":109062584,"uuid":"532700363","full_name":"cloudforet-io/plugin-aws-cloud-service-inven-collector","owner":"cloudforet-io","description":"Plugin for AWS Cloud Service","archived":false,"fork":false,"pushed_at":"2025-09-01T03:18:27.000Z","size":57004,"stargazers_count":7,"open_issues_count":1,"forks_count":11,"subscribers_count":4,"default_branch":"master","last_synced_at":"2025-09-01T05:51:18.317Z","etag":null,"topics":["collector","inventory","plugin"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cloudforet-io.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2022-09-05T01:11:09.000Z","updated_at":"2025-09-01T03:18:32.000Z","dependencies_parsed_at":null,"dependency_job_id":"75f15bea-e165-475f-bdea-6e2e93e89d56","html_url":"https://github.com/cloudforet-io/plugin-aws-cloud-service-inven-collector","commit_stats":null,"previous_names":[],"tags_count":250,"template":false,"template_full_name":null,"purl":"pkg:github/cloudforet-io/plugin-aws-cloud-service-inven-collector","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudforet-io%2Fplugin-aws-cloud-service-inven-collector","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudforet-io%2Fplugin-aws-cloud-service-inven-collector/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudforet-io%2Fplugin-aws-cloud-service-inven-collector/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudforet-io%2Fplugin-aws-cloud-service-inven-collector/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cloudforet-io","download_url":"https://codeload.github.com/cloudforet-io/plugin-aws-cloud-service-inven-collector/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cloudforet-io%2Fplugin-aws-cloud-service-inven-collector/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":273986612,"owners_count":25202704,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-09-06T02:00:13.247Z","response_time":2576,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["collector","inventory","plugin"],"created_at":"2024-12-09T16:15:02.755Z","updated_at":"2025-09-07T01:33:28.124Z","avatar_url":"https://github.com/cloudforet-io.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003ch1 align=\"center\"\u003eAWS Cloud Service Collector\u003c/h1\u003e  \n\n\u003cbr/\u003e  \n\u003cdiv align=\"center\" style=\"display:flex;\"\u003e  \n  \u003cimg width=\"245\" src=\"https://spaceone-custom-assets.s3.ap-northeast-2.amazonaws.com/console-assets/icons/aws-cloudservice.svg\"\u003e\n  \u003cp\u003e \n    \u003cbr\u003e\n    \u003cimg alt=\"Version\"  src=\"https://img.shields.io/badge/version-1.15.8-blue.svg?cacheSeconds=2592000\"  /\u003e    \n    \u003ca href=\"https://www.apache.org/licenses/LICENSE-2.0\"  target=\"_blank\"\u003e\u003cimg alt=\"License: Apache 2.0\"  src=\"https://img.shields.io/badge/License-Apache 2.0-yellow.svg\" /\u003e\u003c/a\u003e \n  \u003c/p\u003e \n\u003c/div\u003e    \n\n**Plugin to collect AWS Cloud Services**\n\n\u003e\nSpaceONE's [plugin-aws-cloud-service-inven-collector](https://github.com/cloudforet-io/plugin-aws-cloud-service-inven-collector)\nis a convenient tool to get cloud service data from AWS.\n\n\nFind us also at [Dockerhub](https://hub.docker.com/repository/docker/spaceone/plugin-aws-cloud-service-inven-collector)\n\u003e Latest stable version : 1.15.8\n\nPlease contact us if you need any further information. (\u003csupport@spaceone.dev\u003e)\n\n---\n\n## Collecting Contents\n\n* Table of Contents\n    * [API Gateway](/src/spaceone/inventory/connector/aws_api_gateway_connector/README.md)\n        * API (REST API / Websocket)\n    * [Auto Scaling Group](/src/spaceone/inventory/connector/aws_auto_scaling_connector/README.md)\n        * Auto Scaling Group\n        * Launch Configuration\n        * Launch Template\n    * [Cloud Front](/src/spaceone/inventory/connector/aws_cloud_front_connector/README.md)\n        * Distribution\n    * [Cloud Trail](/src/spaceone/inventory/connector/aws_cloud_trail_connector/README.md)\n        * Trail\n    * [Direct Connect](/src/spaceone/inventory/connector/aws_direct_connect_connector/README.md)\n        * Connection\n        * Direct Connect Gateway\n        * Virtual Private Gateway\n        * LAG\n    * [DocumentDB](/src/spaceone/inventory/connector/aws_documentdb_connector/README.md)\n        * Cluster\n        * Subnet Group\n        * Parameter Group\n    * [DynamoDB](/src/spaceone/inventory/connector/aws_dynamodb_connector/README.md)\n        * Table\n    * [EBS](/src/spaceone/inventory/connector/aws_ebs_connector/README.md)\n        * Volume\n        * Snapshot\n    * [EC2](/src/spaceone/inventory/connector/aws_ec2_connector/README.md)\n        * Security Group\n        * AMI\n    * [ECR](/src/spaceone/inventory/connector/aws_ecr_connector/README.md)\n        * Repository\n    * [ECS](/src/spaceone/inventory/connector/aws_ecs_connector/README.md)\n        * Cluster\n    * [EFS](/src/spaceone/inventory/connector/aws_efs_connector/README.md)\n        * Filesystem\n    * [EIP](/src/spaceone/inventory/connector/aws_eip_connector/README.md)\n        * EIP\n    * [EKS](/src/spaceone/inventory/connector/aws_eks_connector/README.md)\n        * Cluster\n        * Node Group\n    * [ElastiCache](/src/spaceone/inventory/connector/aws_elasticache_connector/README.md)\n        * Memcached\n        * Redis\n    * [ELB](/src/spaceone/inventory/connector/aws_elb_connector/README.md)\n        * Load Balancer\n        * Target Group\n    * [IAM](/src/spaceone/inventory/connector/aws_iam_connector/README.md)\n        * Group\n        * User\n        * Role\n        * Policy\n        * Identity Provider\n        * Access Key\n    * [Kinesis Datastream](/src/spaceone/inventory/connector/aws_iam_connector/README.md)\n        * Data stream\n    * [Kinesis Firehose](/src/spaceone/inventory/connector/aws_iam_connector/README.md)\n        * Delivery stream\n    * [KMS](/src/spaceone/inventory/connector/aws_kms_connector/README.md)\n        * Key\n    * [Lambda](/src/spaceone/inventory/connector/aws_lambda_connector/README.md)\n        * Function\n        * Layer\n    * [MSK](/src/spaceone/inventory/connector/aws_msk_connector/README.md)\n        * Cluster\n        * Cluster Configuration\n    * [RDS](/src/spaceone/inventory/connector/aws_rds_connector/README.md)\n        * Database\n        * Instance\n        * Snapshot\n        * Subnet Group\n        * Option Group\n    * [Redshift](/src/spaceone/inventory/connector/aws_redshift_connector/README.md)\n        * Cluster\n    * [Route53](/src/spaceone/inventory/connector/aws_route53_connector/README.md)\n        * Hosted Zone\n    * [S3](/src/spaceone/inventory/connector/aws_s3_connector/README.md)\n        * Bucket\n    * [Secrets Manager](/src/spaceone/inventory/connector/aws_secrets_manager_connector/README.md)\n        * Secret\n    * [SNS](/src/spaceone/inventory/connector/aws_sns_connector/README.md)\n        * Topic\n    * [SQS](/src/spaceone/inventory/connector/aws_sqs_connector/README.md)\n        * Queue\n    * [VPC](/src/spaceone/inventory/connector/aws_vpc_connector/README.md)\n        * VPC\n        * Subnet\n        * Route Table\n        * Internet Gateway\n        * Egress only internet Gateway\n        * NAT Gateway\n        * Peer Connection\n        * Network ACL\n        * Endpoint\n        * Transit Gateway\n        * Customer Gateway\n        * VPN Connection\n        * VPN Gateway\n    * [Lightsail](/src/spaceone/inventory/connector/aws_lightsail_connector/README.md)\n        * Instance\n        * Disk\n        * Snapshot\n        * Bucket\n        * Static IP\n        * Database\n        * Container\n        * Load Balancer\n        * Distribution\n\n---\n\n## AWS Service Endpoint (in use)\n\nThere is an endpoints used to collect AWS resources information.\nAWS endpoint is a URL consisting of a region and a service code.\n\u003cpre\u003e\nhttps://[service-code].[region-code].amazonaws.com\n\u003c/pre\u003e\n\nWe use hundreds of endpoints because we collect information from a lots of regions and services.\n\n### Region list\n\nBelow is the AWS region information.\nThe regions we collect are not all regions supported by AWS. Exactly, we target the regions results returned\nby [describe_regions()](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/ec2.html#EC2.Client.describe_regions)\nof AWS ec2 client.\n\n| No. | Region name               | Region Code    |\n|-----|---------------------------|----------------|\n| 1   | US East (Ohio)            | us-east-2      |\n| 2   | US East (N. Virginia)     | us-east-1      |\n| 3   | US West (N. California)   | us-west-1      |\n| 4   | US West (Oregon)          | us-west-2      |\n| 5   | Asia Pacific (Mumbai)     | ap-south-1     |\n| 6   | Asia Pacific (Osaka)      | ap-northeast-3 |\n| 7   | Asia Pacific (Seoul)      | ap-northeast-2 |\n| 8   | Asia Pacific (Singapore)  | ap-southeast-1 |\n| 9   | Asia Pacific (Sydney)     | ap-southeast-2 |\n| 10  | Asia Pacific (Tokyo)      | ap-northeast-1 |\n| 11  | Canada (Central)          | ca-central-1   |\n| 12  | Europe (Frankfurt)        | eu-central-1   |\n| 13  | Europe (Ireland)          | eu-west-1      |\n| 14  | Europe (London)           | eu-west-2      |\n| 15  | Europe (Paris)            | eu-west-3      |\n| 16  | Europe (Stockholm)        | eu-north-1     |\n| 17  | South America (São Paulo) | sa-east-1      |\n\n### Service list\n\nThe following is a list of services being collected and service code information.\n\n| No. | Service name                             | Service Code          |\n|-----|------------------------------------------|-----------------------|\n| 1   | AWS Certifcate Manager                   | AWSCertificateManager |\n| 2   | API Gateway (REST API)                   | AmazonApiGateway      |\n| 3   | API Gateway V2 (Websocket)               | AmazonApiGateway      |\n| 4   | Auto Scaling Group                       | AmazonEC2             |\n| 5   | CloudFront                               | AmazonCloudFront      |\n| 6   | CloudTrail                               | AWSCloudTrail         |\n| 7   | Direct Connect                           | AWSDirectConnect      |\n| 8   | DocumentDB                               | AmazonDocDB           |\n| 9   | DynamoDB                                 | AmazonDynamoDB        |\n| 10  | Elastic Block Store (EBS)                | AmazonEC2             |\n| 11  | EC2 (SecurityGroup, AMI, EIP)            | AmazonEC2             |\n| 12  | Elastic Container Registry (ECR)         | AmazonECR             |\n| 13  | Elastic Container Service (ECS)          | AmazonECS             |\n| 14  | Elastic File System (EFS)                | AmazonEFS             |\n| 15  | Elastic Kubernetes Service (EKS)         | AmazonEKS             |\n| 16  | Elasticache                              | AmazonElastiCache     |\n| 17  | Elastic Load Balancer (ELB)              | AWSELB                |\n| 18  | Identity Access Management (IAM)         | -                     |\n| 19  | Kinesis Data Stream                      | AmazonKinesis         |\n| 20  | Kinesis Firehose                         | AmazonKinesisFirehose |\n| 21  | Key Management System (KMS)              | awskms                |\n| 22  | Lambda                                   | AWSLambda             |\n| 21  | Managed Streaming for Apache Kafka (MSK) | AmazonMSK             |\n| 22  | Relational Database Service (RDS)        | AmazonRDS             |\n| 23  | Redshift                                 | AmazonRedshift        |\n| 24  | Route53                                  | AmazonRoute53         |\n| 25  | Simple Cloud Storage (S3)                | AmazonS3              |\n| 26  | Secrets Manager                          | AWSSecretsManager     |\n| 27  | Simple Notification Service (SNS)        | AmazonSNS             |\n| 28  | Simple Queue Service (SQS)               | AWSQueueService       |\n| 29  | Virtual Private Cloud (VPC)              | AmazonVPC             |\n| 30  | Lightsail                                | AmazonLightsail       |\n\n---\n\n## Authentication Overview\n\nRegistered service account on SpaceONE must have certain permissions to collect cloud service data Please, set\nauthentication privilege for followings:\n\n\u003cpre\u003e\n\u003ccode\u003e\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Action\": [\n                \"acm:Describe*\",\n                \"acm:List*\",\n                \"apigateway:GET\",\n                \"application-autoscaling:Describe*\",\n                \"autoscaling:Describe*\",\n                \"cloudfront:List*\",\n                \"cloudtrail:Describe*\",\n                \"cloudtrail:Get*\",\n                \"cloudtrail:List*\",\n                \"cloudwatch:Describe*\",\n                \"cloudwatch:Get*\",\n                \"cloudwatch:List*\",\n                \"directconnect:Describe*\",\n                \"dynamodb:Describe*\",\n                \"dynamodb:List*\",\n                \"ec2:Describe*\",\n                \"ecr:Describe*\",\n                \"ecr:List*\",\n                \"ecs:Describe*\",\n                \"ecs:List*\",\n                \"eks:Describe*\",\n                \"eks:List*\",\n                \"elasticache:Describe*\",\n                \"elasticache:List*\",\n                \"elasticfilesystem:Describe*\",\n                \"elasticloadbalancing:Describe*\",\n                \"firehose:Describe*\",\n                \"firehose:List*\",\n                \"health:Describe*\",\n                \"iam:Get*\",\n                \"iam:List*\",\n                \"kafka:Describe*\",\n                \"kafka:List*\",\n                \"kinesis:Describe*\",\n                \"kinesis:List*\",\n                \"kms:Describe*\",\n                \"kms:Get*\",\n                \"kms:List*\",\n                \"lambda:List*\",\n                \"lambda:Get*\",\n                \"rds:Describe*\",\n                \"rds:List*\",\n                \"redshift:Describe*\",\n                \"route53:List*\",\n                \"s3:Get*\",\n                \"s3:List*\",\n                \"secretsmanager:List*\",\n                \"sns:Get*\",\n                \"sns:List*\",\n                \"sqs:Get*\",\n                \"sqs:List*\",\n                \"ssm:Describe*\",\n                \"Lightsail:Get*\"\n            ],\n            \"Effect\": \"Allow\",\n            \"Resource\": \"*\"\n        }\n    ]\n}\n\u003c/code\u003e\n\u003c/pre\u003e\n\n\n---\n\n## Options\n\n### Cloud Service Type : Specify what to collect\n\nIf cloud_service_types is added to the list elements in options, only the specified cloud service type is collected.\nBy default, if cloud_service_types is not specified in options, all services are collected.\n\nThe cloud_service_types items that can be specified are as follows.\n\n\u003cpre\u003e\n\u003ccode\u003e\n{\n    \"cloud_service_types\": [\n        'IAM',          \n        'DynamoDB',     \n        'Lambda',       \n        'CloudFront',\n        'RDS',\n        'Route53',\n        'S3',\n        'AutoScalingGroup',\n        'ElastiCache',\n        'APIGateway',\n        'DirectConnect',\n        'EFS',\n        'DocumentDB',\n        'ECS',\n        'Redshift',\n        'EKS',\n        'SQS',\n        'KMS',\n        'ECR',\n        'CloudTrail',\n        'SNS',\n        'SecretsManager',\n        'ELB',\n        'EIP',\n        'EBS',\n        'VPC',\n        'EC2',\n        'ACM',\n        'KinesisDataStream',\n        'KinesisFirehose',\n        'MSK',\n        'Lightsail'\n    ]\n}\n\u003c/code\u003e\n\u003c/pre\u003e\n\n---\n## Secret Data Configuration\n\nTo use the EC2 Collector plugin, AWS authentication information is required. You can configure authentication information using the following methods.\n\n### 1. General Access Key Method (Single Account)\n\nThis method is used when collecting resources within the same AWS account.\n\n#### Secret Data Format:\n```json\n{\n    \"aws_access_key_id\": \"YOUR_ACCESS_KEY_ID\",\n    \"aws_secret_access_key\": \"YOUR_SECRET_ACCESS_KEY\"\n}\n```\n\n#### Setup Method:\n\n1. **Create IAM User in AWS Console**\n   - AWS Console → IAM → Users → Create User\n   - Enter user name (e.g., spaceone-collector)\n   - Select Access Key creation option\n\n2. **Attach Managed Policy**\n   - Select one of the managed policies provided by AWS:\n     - `ReadOnlyAccess`: Read-only permissions for all AWS services\n     - Or use custom policy that includes only necessary services\n\n3. **Create Access Key**\n   - IAM User → Security credentials → Create access key\n   - Save Access Key ID and Secret Access Key in a secure location\n\n### 2. Cross-Account Assume Role Method (Multi-Account)\n\nThis method is used when collecting resources from different AWS accounts.\n\n#### Secret Data Format:\n```json\n{\n    \"aws_access_key_id\": \"SOURCE_ACCOUNT_ACCESS_KEY_ID\",\n    \"aws_secret_access_key\": \"SOURCE_ACCOUNT_SECRET_ACCESS_KEY\",\n    \"role_arn\": \"arn:aws:iam::TARGET_ACCOUNT_ID:role/ROLE_NAME\",\n    \"external_id\": \"OPTIONAL_EXTERNAL_ID\"\n}\n```\n\n#### Setup Method:\n\n**Source Account (Account that runs collection) Setup:**\n1. **Create IAM User and Set Permissions**\n   - AWS Console → IAM → Users → Create User\n   - Enter user name (e.g., spaceone-cross-account-collector)\n   - Create Access Key\n   - Attach `ReadOnlyAccess` policy\n\n**Target Account (Account whose resources will be collected) Setup:**\n1. **Create Cross-Account Role**\n   ```json\n   {\n       \"Version\": \"2012-10-17\",\n       \"Statement\": [\n           {\n               \"Effect\": \"Allow\",\n               \"Principal\": {\n                   \"AWS\": \"arn:aws:iam::SOURCE_ACCOUNT_ID:user/SOURCE_USER_NAME\"\n               },\n               \"Action\": \"sts:AssumeRole\",\n               \"Condition\": {\n                   \"StringEquals\": {\n                       \"sts:ExternalId\": \"YOUR_EXTERNAL_ID\"\n                   }\n               }\n           }\n       ]\n   }\n   ```\n\n2. **Attach Managed Policy to Role**\n   - Attach `ReadOnlyAccess` policy to the created Role\n   - Or attach custom policy that includes only necessary services\n---\n\nHow to update plugin information using spacectl is as follows.\nFirst, create a yaml file to set options.\n\n\u003cpre\u003e\n\u003ccode\u003e\n\u003e cat update_collector.yaml\n---\ncollector_id: collector-xxxxxxx\noptions:\n  cloud_service_types:\n    - EC2\n    - RDS\n    - ELB\n\u003c/code\u003e\n\u003c/pre\u003e\n\nUpdate plugin through spacectl command with the created yaml file.\n\n### Service Code Mapper : Convert service code in Cloud Service Type what you want.\n\nIf `service_code_mappers` is added in options, You can replace the service code specified in the cloud service type.\nThe service code set by default can be checked in the Service List item of this document.\n\nThe `service_code_mappers` items that can be specified are as follows.\n\n\u003cpre\u003e\n\u003ccode\u003e\n{\n    \"service_code_mappers\": {\n        \"AmazonEC2\": \"Amazon Elastic Computing\",\n        \"AmazonRDS\": \"Amazon Relation Database\",\n    }\n}\n\u003c/code\u003e\n\u003c/pre\u003e\n\n### Custom Asset URL : Possible to modify icon path of cloud service\n\nIf `custom_asset_url` is added in options, You can replace the path of the icon each cloud service type instead of\ndefault path.\n\nThe `custom_asset_url` items that can be specified are as follows.\n\n\u003cpre\u003e\n\u003ccode\u003e\n{\n    \"custom_asset_url\": \"https://CUSTOM_ASSET_URL/...\"\n}\n\u003c/code\u003e\n\u003c/pre\u003e\n---\n\n## Release note\n\n| Version | Description                                                                                                                                                                                                                                                                                                                                                               | Affected Service                                    | Release Date |\n|---------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------|--------------|\n| 1.15.59   | Add listener rules detail data                                                                                                                                                                                                                                                          | ELB\u003eLoadBalancer                                        | 2025.04.22   |\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloudforet-io%2Fplugin-aws-cloud-service-inven-collector","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcloudforet-io%2Fplugin-aws-cloud-service-inven-collector","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcloudforet-io%2Fplugin-aws-cloud-service-inven-collector/lists"}