{"_id":"@codyswann/aws-soc2-setup","name":"@codyswann/aws-soc2-setup","dist-tags":{"latest":"1.1.2"},"versions":{"1.1.2":{"devDependencies":{"@ast-grep/cli":"^0.42.0","@codyswann/lisa":"^2.191.5","@commitlint/cli":"^20.0.0","@commitlint/config-conventional":"^20.0.0","@types/node":"^22.19.19","@vitest/coverage-v8":"^4.1.0","aws-sdk-client-mock":"^4.1.0","eslint":"^10.0.3","eslint-plugin-oxlint":"^1.62.0","eslint-plugin-sonarjs":"^4.0.3","husky":"^8.0.0","knip":"^5.88.1","oxlint":"^1.62.0","oxlint-tsgolint":"^0.22.1","prettier":"^3.8.1","semver":"^7.8.1","standard-version":"^9.5.0","tsup":"^8.5.1","typescript":"^6.0.3","vitest":"^4.1.0"},"scripts":{"build":"tsup","postinstall":"[ -n \"$CI\" ] || node node_modules/@codyswann/lisa/dist/index.js --yes --skip-git-check . 2>/dev/null || true","test:integration":"vitest run tests/integration --passWithNoTests","dev":"tsup --watch","typecheck":"tsc --noEmit","test":"vitest run","test:unit":"vitest run --exclude='**/integration/**'","test:cov":"vitest run --coverage","test:watch":"vitest","lint":"oxlint && eslint . --quiet","lint:fix":"oxlint --fix && eslint . --fix","lint:slow":"eslint . --config eslint.slow.config.ts --quiet","format":"prettier --check . --write","format:check":"prettier --check .","knip":"knip","knip:fix":"knip --fix","sg:scan":"ast-grep scan","setup:deploy-key":"setup-deploy-key","prepublishOnly":"$npm_execpath run build","prepare":"node -e \"if (process.env.INIT_CWD && process.env.INIT_CWD.includes('.serverless')) { process.exit(0); }\" && husky install || true"},"engines":{"npm":"please-use-bun","yarn":"please-use-bun","pnpm":"please-use-bun","bun":"1.3.8","node":">=18"},"name":"@codyswann/aws-soc2-setup","version":"1.1.2","description":"Automated AWS Control Tower setup for SOC 2 compliance — account provisioning, IAM Identity Center, security services, backup, and KMS as a typed CLI","type":"module","main":"./dist/cli.js","bin":{"aws-soc2-setup":"bin/aws-soc2-setup.js"},"repository":{"type":"git","url":"git+https://github.com/CodySwannGT/aws-soc2-setup.git"},"homepage":"https://github.com/CodySwannGT/aws-soc2-setup#readme","bugs":{"url":"https://github.com/CodySwannGT/aws-soc2-setup/issues"},"author":{"name":"Cody Swann"},"license":"MIT","keywords":["aws","soc2","control-tower","compliance","iam-identity-center","cli","security"],"dependencies":{"@aws-sdk/client-auditmanager":"^3.1063.0","@aws-sdk/client-backup":"^3.1063.0","@aws-sdk/client-config-service":"^3.1063.0","@aws-sdk/client-controltower":"^3.1063.0","@aws-sdk/client-eventbridge":"3.1063.0","@aws-sdk/client-guardduty":"^3.1063.0","@aws-sdk/client-iam":"^3.1063.0","@aws-sdk/client-identitystore":"^3.1063.0","@aws-sdk/client-inspector2":"^3.1063.0","@aws-sdk/client-kms":"^3.1063.0","@aws-sdk/client-macie2":"^3.1063.0","@aws-sdk/client-organizations":"^3.1063.0","@aws-sdk/client-s3":"^3.1063.0","@aws-sdk/client-securityhub":"^3.1063.0","@aws-sdk/client-service-catalog":"^3.1063.0","@aws-sdk/client-sns":"3.1063.0","@aws-sdk/client-sso-admin":"^3.1063.0","@aws-sdk/client-sts":"^3.1063.0","@aws-sdk/credential-providers":"^3.1063.0","chalk":"^5.6.2","commander":"^14.0.3"},"resolutions":{"@isaacs/brace-expansion":"^5.0.1","axios":">=1.15.2","picomatch":">=4.0.4","minimatch":">=10.2.1","yaml":">=2.8.3","smol-toml":">=1.6.1","handlebars":">=4.7.9","esbuild":">=0.28.1","lodash":">=4.18.1","vite":"$vite","ws":">=8.21.0","form-data":">=4.0.6","multer":">=2.2.0","undici":">=6.27.0"},"overrides":{"@isaacs/brace-expansion":"^5.0.1","axios":">=1.15.2","picomatch":">=4.0.4","minimatch":">=10.2.1","yaml":">=2.8.3","smol-toml":">=1.6.1","handlebars":">=4.7.9","esbuild":">=0.28.1","lodash":">=4.18.1","ws":">=8.21.0","form-data":">=4.0.6","multer":">=2.2.0","undici":">=6.27.0","@smithy/types":"4.16.1"},"trustedDependencies":["@ast-grep/cli","@codyswann/lisa","@sentry/cli"],"_id":"@codyswann/aws-soc2-setup@1.1.2","gitHead":"435431ff176f0296c535acfe7a24fa33ac403e36","types":"./dist/cli.d.ts","_nodeVersion":"22.22.0","_npmVersion":"10.9.4","dist":{"integrity":"sha512-gh1eDM1Oa7FRcK2AOjhr+09q2zgkkkKn2hJzm+vBcDx0Wg1f+VbQa1VdPr3hhq0hVO/Xl53V6tOVvPJaoLjFtg==","shasum":"b98f198b2ca6ba4bc18d76f0dff652215ba9099f","tarball":"https://registry.npmjs.org/@codyswann/aws-soc2-setup/-/aws-soc2-setup-1.1.2.tgz","fileCount":7,"unpackedSize":482573,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIEiv35zq/7fBe5NVJtmesGxUTUxR2O8m0wrPhGiIdb4/AiBu24tHxBxnoSkYhnMXU8OVrN6GNQS94IYER3WwBMmoJQ=="}]},"_npmUser":{"name":"codyswann","email":"cody@gunnertech.com"},"directories":{},"maintainers":[{"name":"codyswann","email":"cody@gunnertech.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aws-soc2-setup_1.1.2_1783793637871_0.33527741741101247"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-11T18:13:57.755Z","1.1.2":"2026-07-11T18:13:58.018Z","modified":"2026-07-11T18:13:58.177Z"},"maintainers":[{"name":"codyswann","email":"cody@gunnertech.com"}],"description":"Automated AWS Control Tower setup for SOC 2 compliance — account provisioning, IAM Identity Center, security services, backup, and KMS as a typed CLI","homepage":"https://github.com/CodySwannGT/aws-soc2-setup#readme","keywords":["aws","soc2","control-tower","compliance","iam-identity-center","cli","security"],"repository":{"type":"git","url":"git+https://github.com/CodySwannGT/aws-soc2-setup.git"},"author":{"name":"Cody Swann"},"bugs":{"url":"https://github.com/CodySwannGT/aws-soc2-setup/issues"},"license":"MIT","readme":"# AWS Control Tower SOC 2 Automation Suite\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)\n[![npm](https://img.shields.io/npm/v/@codyswann/aws-soc2-setup.svg)](https://www.npmjs.com/package/@codyswann/aws-soc2-setup)\n[![SOC 2 aligned](https://img.shields.io/badge/SOC%202-aligned-green)](https://www.aicpa.org/interestareas/frc/assuranceadvisoryservices/soc2relevantguidance.html)\n[![AWS Control Tower](https://img.shields.io/badge/AWS-Control%20Tower-orange)](https://aws.amazon.com/controltower/)\n\n> Open-source TypeScript CLI for SOC 2–aligned AWS Control Tower environments\n\n`aws-soc2-setup` turns the usual multi-day Control Tower + SOC 2 bootstrap into a guided, skip-friendly workflow: Identity Center, organizational units, security services, controls, backup, KMS, and root lockdown.\n\n> **New here?** Durable project knowledge lives in the [LLM Wiki](wiki/start-here.md). Browse [`wiki/index.md`](wiki/index.md) or run `/onboard-me` (Codex: `$lisa-wiki-onboard-me`).\n\n## Table of contents\n\n- [Overview](#overview)\n- [Features](#features)\n- [Install](#install)\n- [Quick start](#quick-start)\n- [Commands](#commands)\n- [Setup plan](#setup-plan)\n- [Security considerations](#security-considerations)\n- [Development](#development)\n- [Contributing](#contributing)\n- [License](#license)\n- [Disclaimer](#disclaimer)\n\n## Overview\n\nThis package is a typed Node.js CLI (`aws-soc2-setup`) published as [`@codyswann/aws-soc2-setup`](https://www.npmjs.com/package/@codyswann/aws-soc2-setup). It uses AWS SDK v3 under the hood and replaces the earlier Bash suite with the same domain coverage:\n\n| Domain | What it covers |\n| --- | --- |\n| **setup** | 16-step orchestrator (plan + automatable steps) |\n| **status** / **whoami** | Environment readiness and caller identity |\n| **sso** | IAM Identity Center users, groups, assignments, profile config |\n| **controltower** | OUs, Account Factory provisioning, Control Tower controls |\n| **security** | GuardDuty, Security Hub, Config, Macie, Inspector, Audit Manager |\n| **backup** | AWS Backup vault/plan + delegated admin |\n| **kms** | Key administrators and rotation |\n| **root** | Delete root access keys; org-wide root credential removal |\n| **scp** | Deny long-lived IAM credentials org-wide; management-account creation alerts |\n\nManual console steps (root MFA, enabling Identity Center, landing zone creation) stay explicit in the plan — the CLI does not pretend those are fully automatable.\n\n## Features\n\n- **Guided setup** — `setup` prints the ordered plan and runs the automatable steps\n- **Dry-run safe** — global `--dry-run` previews mutating work; `status` is always read-only\n- **Multi-account architecture** — management, audit, log archive, and workload accounts via Control Tower\n- **IAM Identity Center** — users, groups, and permission-set assignment instead of long-lived IAM users\n- **SOC 2–oriented controls** — security services, Control Tower guardrails, backup, and KMS\n- **Root protection** — delete root keys and remove root credentials from member accounts\n- **Open source** — MIT licensed; contributions welcome\n\n## Install\n\n**Requirements:** Node.js 18+, AWS credentials (CLI profile or default chain), and an AWS account where you can enable Organizations / Control Tower.\n\n```bash\n# one-shot\nnpx @codyswann/aws-soc2-setup --help\n\n# or install globally\nnpm install -g @codyswann/aws-soc2-setup\naws-soc2-setup --help\n```\n\nFrom a clone of this repo (Bun is the package manager):\n\n```bash\ngit clone https://github.com/CodySwannGT/aws-soc2-setup.git\ncd aws-soc2-setup\nbun install\nbun run build\n./bin/aws-soc2-setup.js --help\n```\n\n## Quick start\n\n```bash\n# Confirm credentials\naws-soc2-setup whoami -p your-admin-profile\n\n# See what the environment already has\naws-soc2-setup status -p your-admin-profile\n\n# Preview the full setup plan (no changes)\naws-soc2-setup setup --dry-run -p your-admin-profile\n\n# Run automatable steps (OUs, security services, optional controls/backup/audit)\naws-soc2-setup setup -p your-admin-profile \\\n  --ou ou-xxxx-xxxxxxxx \\\n  --central-account 111122223333 \\\n  --admin-account 444455556666 \\\n  --audit-account 777788889999\n```\n\n**Global options** (apply to every command):\n\n| Flag | Description |\n| --- | --- |\n| `-p, --profile <profile>` | AWS CLI profile |\n| `-r, --region <region>` | Region (default: `AWS_REGION` or `us-east-1`) |\n| `--dry-run` | Preview mutating actions without applying them |\n| `-y, --yes` | Skip confirmation prompts (required for destructive `root` ops) |\n\n## Commands\n\n| Command | Purpose |\n| --- | --- |\n| `status` | Read-only readiness: credentials, Organizations, recommended OUs, Identity Center, member accounts |\n| `whoami` | Print STS caller identity |\n| `setup` | Print the 21-step plan and run automatable steps |\n| `sso create-user` / `group` / `assign` | Identity Center users, groups, permission sets |\n| `sso configure-profile` / `set-start-url` | Local SSO profile and start URL |\n| `controltower create-organization` | Create AWS Organizations (`FeatureSet=ALL`) if missing |\n| `controltower create-ous` | Create Infrastructure / Workloads / Sandbox OUs |\n| `controltower register-ou` | Register an OU with Control Tower (`EnableBaseline`) |\n| `controltower provision-account` | Account Factory provisioning (`--wait` supported) |\n| `controltower enable-controls` | Enable Control Tower controls for an OU |\n| `security enable` | Enable GuardDuty, Security Hub, Config, Macie, Inspector |\n| `security audit` | Config aggregator (+ Audit Manager only if already enabled; unavailable for new accounts after 2026-04-30) |\n| `security conformance-packs` | Deploy AWS Config sample Conformance Packs (CIS / WA Security / CT detective) |\n| `backup` | Configure AWS Backup (vault, plan, delegated admin) |\n| `kms` | Manage key administrators and rotation |\n| `root delete-keys` / `remove-access` | Root key deletion and org-wide root lockdown (`--yes` required) |\n| `scp deny-iam-users` | SCP denying IAM user / access key / login profile creation, attached to the org root or given OUs (`--yes` required; `--exempt-arn` for break-glass) |\n| `scp alert-management` | EventBridge → SNS email alert on IAM credential creation — detective coverage for the management account, which SCPs cannot bind (`--yes` required; run in us-east-1) |\n\nRun `aws-soc2-setup <command> --help` for flags on each subcommand.\n\n## Setup plan\n\n`setup` follows this sequence. Automated steps run when you invoke `setup` (with the options they need); manual steps are printed as guidance.\n\n| # | Step | Kind |\n| --- | --- | --- |\n| 1 | Initial AWS CLI / SSO profile setup | Manual (`sso configure-profile`) |\n| 2 | Enable MFA for the root user | Manual (console) |\n| 3 | Create AWS Organizations | Automated (`controltower create-organization`) |\n| 4 | Enable IAM Identity Center | Manual (console) |\n| 5 | Set up AWS Control Tower landing zone | Manual (console) |\n| 6 | Create the admin user | Manual (`sso create-user`, `sso assign`, `root delete-keys`) |\n| 7 | Create the initial users group | Manual (`sso group`) |\n| 8 | Create additional users | Manual (`sso create-user` / `sso group`) |\n| 9 | Create organizational units | Automated (`controltower create-ous --all`) |\n| 10 | Register OUs with Control Tower | Automated (`controltower register-ou`) |\n| 11 | Enable security services | Automated (`security enable --all`) |\n| 12 | Enable Control Tower controls | Automated (`controltower enable-controls`) |\n| 13 | Configure AWS Backup | Automated (`backup`) |\n| 14 | Configure audit and reporting | Automated (`security audit`) |\n| 15 | Deploy Config Conformance Packs | Automated (`security conformance-packs --preset recommended`) |\n| 16 | Provision additional accounts | Manual (`controltower provision-account`) |\n| 17 | Custom Identity Center domain | Manual (`sso set-start-url`) |\n| 18 | Disable root access for sub-accounts | Manual (`root remove-access --yes`) |\n| 19 | Configure KMS key management | Manual (`kms`) |\n| 20 | Block long-lived IAM credentials | Manual (`scp deny-iam-users --yes`) |\n| 21 | Alert on management-account IAM credential creation | Manual (`scp alert-management -e <email> --yes`) |\n\nTrack progress with [`docs/CHECKLIST.md`](docs/CHECKLIST.md).\n\n## Security considerations\n\n- **Root access keys** may be created temporarily during bootstrap; delete them promptly (`root delete-keys`). If a run is interrupted, remove any leftover root keys manually.\n- **The management account is exempt from SCPs by AWS design** — `scp deny-iam-users` protects every member account, but cannot prevent IAM user creation in the management account itself. Pair it with `scp alert-management` (detection) and keep workloads out of the management account.\n- **`root remove-access`** is destructive and requires `--yes`. Review member accounts before running it.\n- **New Account Factory accounts** do not automatically inherit every security service. Re-run `security enable` (or `setup`) after provisioning.\n- **Least privilege** — prefer Identity Center permission sets over long-lived IAM users; review cross-account roles regularly.\n- This tool helps implement *technical* controls relevant to SOC 2. It does **not** guarantee a successful audit.\n\n## Development\n\n```bash\nbun install\nbun run build\nbun run test\nbun run lint\nbun run typecheck\n```\n\nSource lives under `src/` (commands, domain modules, shared `lib/`). Tests mirror that layout under `tests/` (Vitest + `aws-sdk-client-mock`).\n\n## Contributing\n\nContributions are welcome — see [CONTRIBUTING.md](CONTRIBUTING.md). Open issues and pull requests against [CodySwannGT/aws-soc2-setup](https://github.com/CodySwannGT/aws-soc2-setup).\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n\n## Disclaimer\n\nThis suite helps implement technical controls relevant to SOC 2 compliance but does not guarantee a successful audit. Work with qualified auditors for your organization's specific requirements.\n","readmeFilename":"README.md","_rev":"1-897a60ad40ed78dfb90afb891bc67546"}