Quickstart¶
Get iam-zero up and running in under 5 minutes.
1. Install¶
pip install zero-iam
pipx install zero-iam
brew tap MaripeddiSupraj/tap
brew install iam-zero
2. Configure¶
iam-zero configure
This will prompt you for:
- Anthropic API key — required for Claude-powered analysis
- GitHub personal access token (optional) — needed only for
--githubmode - Default repo (owner/repo) (optional) — needed only for
--githubmode
3. Enable Cloud APIs¶
Ensure your caller identity has the following permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"cloudtrail:LookupEvents",
"iam:GenerateServiceLastAccessedDetails",
"iam:GetServiceLastAccessedDetails",
"iam:GetRole",
"iam:ListAttachedRolePolicies",
"iam:GetPolicy",
"iam:GetPolicyVersion",
"iam:ListRolePolicies",
"iam:GetRolePolicy"
],
"Resource": "*"
}
]
}
gcloud services enable \
cloudresourcemanager.googleapis.com \
logging.googleapis.com \
iam.googleapis.com \
--project YOUR-PROJECT
Your caller identity needs:
- resourcemanager.projects.getIamPolicy
- logging.logEntries.list
4. Scan a Role¶
iam-zero scan aws --role arn:aws:iam::123456789012:role/my-role
iam-zero scan gcp \
--service-account sa@my-project.iam.gserviceaccount.com \
--project my-project
That's it! The output will show findings in a clean terminal table.
Safe by default
All scans run in dry-run mode by default. Nothing is written or modified until you explicitly pass --output or --github.