Skip to content

runbooks inventoryΒΆ

Auto-generated from runbooks inventory --help on 2026-05-21. Source of truth: runbooks PyPI package v1.3.22

Runbooks Inventory - Multi-account AWS resource discovery

πŸ“‹ Command Categories (40 operations across 9 categories):
1️⃣  Discovery: resource-explorer (88 AWS resource types)
2️⃣  Organizations: org-*, accounts-* (multi-account management)
3️⃣  VPC/Network: vpc-*, nat-*, elb-* (network architecture)
4️⃣  CloudFormation: cfn-*, stack-* (IaC drift detection)
5️⃣  Activity/Scoring: enrich-*, score-* (decommission analysis)
6️⃣  Security/Compliance: security-*, audit-*, check-*
7️⃣  Workflows: workflow-*, pipeline-* (automated pipelines)
8️⃣  Validation: validate-*, verify-* (MCP cross-validation)
9️⃣  Utilities: export-*, clean-*, show-* (helper commands)

Inventory Commands (59 commands)
β”œβ”€β”€ πŸ” Multi-Account Discovery (6 commands)
β”‚   └──   Command                              Description                      
β”‚         collect                              Multi-account resource           
β”‚                                              discovery via Resource Explorer  
β”‚         resource-explorer                    Discover resources by friendly   
β”‚                                              alias (88 types)                 
β”‚         resource-types                       List all 88 supported resource   
β”‚                                              types                            
β”‚         discover-rds                         RDS database discovery           
β”‚         discover-lambda                      Lambda function discovery        
β”‚         collect-containers                   Container discovery (ECS         
β”‚                                              clusters, tasks, services)       
β”œβ”€β”€ 🏒 Organizations (14 commands)
β”‚   └──   Command                              Description                      
β”‚         list-org-accounts                    List AWS accounts in             
β”‚                                              organization                     
β”‚         list-org-users                       List IAM users across            
β”‚                                              organization                     
β”‚         draw-org                             Visualize organization           
β”‚                                              hierarchy                        
β”‚         check-landingzone                    Validate Landing Zone            
β”‚                                              configuration                    
β”‚         check-controltower                   Validate Control Tower setup     
β”‚         find-lz-versions                     Discover Landing Zone versions   
β”‚         collect-ram-shares                   Discover AWS RAM shares          
β”‚         list-enabled-services                List Organizations-enabled       
β”‚                                              service principals               
β”‚         list-delegated-administrators        List Organizations delegated     
β”‚                                              administrators                   
β”‚         list-org-policies                    List Organizations policies      
β”‚                                              (SCP/Tag/Backup/AI)              
β”‚         list-resource-groups                 List AWS Resource Groups in      
β”‚                                              region                           
β”‚         list-app-registry-applications       List Service Catalog             
β”‚                                              AppRegistry applications         
β”‚         describe-delegated-admin-policy      Describe Organization            
β”‚                                              resource-based (trust) policy    
β”‚         org-governance-report                AWS Organizations governance     
β”‚                                              dashboard β€” accounts, SCPs,      
β”‚                                              services, delegated admins       
β”œβ”€β”€ πŸ”„ Enrichment Layers (5 commands)
β”‚   └──   Command                              Description                      
β”‚         enrich-accounts                      Add Organizations metadata       
β”‚         enrich-costs                         Add cost data from Cost          
β”‚                                              Explorer                         
β”‚         enrich-activity                      Add CloudTrail activity signals  
β”‚         enrich-ec2                           EC2-specific enrichment          
β”‚         score-decommission                   Score decommission candidates    
β”‚                                              (E1-E7/W1-W6)                    
β”œβ”€β”€ 🌐 VPC & Network (via `inventory vpc` subgroup) (7 commands)
β”‚   └──   Command                              Description                      
β”‚         vpc flow-logs                        VPC Flow Logs discovery and      
β”‚                                              analysis                         
β”‚         vpc nat-traffic                      NAT Gateway traffic analysis     
β”‚         vpc security-groups                  Security group validation        
β”‚         vpc validate                         VPC architecture assessment      
β”‚         vpc dependencies                     Cross-VPC dependency analysis    
β”‚         list-elbs                            Load balancer discovery          
β”‚                                              (ELB/ALB/NLB)                    
β”‚         list-enis                            Network interface discovery      
β”‚                                              (ENI)                            
β”œβ”€β”€ ☁️ CloudFormation (6 commands)
β”‚   └──   Command                              Description                      
β”‚         find-cfn-drift                       CloudFormation drift detection   
β”‚         find-cfn-orphaned-stacks             Orphaned stack discovery         
β”‚         list-cfn-stacks                      List CloudFormation stacks       
β”‚         list-cfn-stacksets                   List CloudFormation StackSets    
β”‚         find-cfn-stackset-drift              StackSet drift detection         
β”‚         recover-cfn-stack-ids                Recover CloudFormation stack     
β”‚                                              IDs                              
β”œβ”€β”€ πŸ”’ Security & Compliance (6 commands)
β”‚   └──   Command                              Description                      
β”‚         check-cloudtrail-compliance          CloudTrail compliance            
β”‚                                              validation                       
β”‚         list-guardduty-detectors             GuardDuty detector discovery     
β”‚         tag-coverage                         Tag coverage analysis            
β”‚         drift-detection                      Comprehensive drift detection    
β”‚         ssm-status                           SSM Agent status for EC2         
β”‚                                              instance (ssm_agent_status,      
β”‚                                              ssm_ping_status)                 
β”‚         ebs-health                           EBS volume health and            
β”‚                                              attachment status for EC2        
β”‚                                              instance                         
β”œβ”€β”€ πŸ“‘ Other Services (3 commands)
β”‚   └──   Command                              Description                      
β”‚         list-sns-topics                      SNS topic discovery              
β”‚         collect-messaging                    Messaging resources (SQS         
β”‚                                              queues, SNS topics)              
β”‚         collect-analytics                    Analytics resources (Athena,     
β”‚                                              Glue databases/tables)           
β”œβ”€β”€ πŸš€ Workflows (3 commands)
β”‚   └──   Command                              Description                      
β”‚         workflow-single-account              4-layer pipeline (single         
β”‚                                              account)                         
β”‚         workflow-multi-account               5-layer pipeline (multi-account  
β”‚                                              LZ)                              
β”‚         pipeline-summary                     Display pipeline execution       
β”‚                                              summary                          
β”œβ”€β”€ βœ… Validation (3 commands)
β”‚   └──   Command                              Description                      
β”‚         validate-mcp                         MCP cross-validation (β‰₯99.5%     
β”‚                                              accuracy)                        
β”‚         validate-costs                       Cost data accuracy validation    
β”‚         cross-validate                       4-way cross-validation           
β”‚                                              (MCP/CLI/Console/AWS)            
β”œβ”€β”€ πŸ› οΈ Utilities (1 commands)
β”‚   └──   Command                              Description             
β”‚         clean-outputs                        Clean output directory  
└── πŸ” Resource Investigation (5 commands)
    └──   Command                              Description                      
          ec2-investigate                      6-phase EC2 host investigation   
                                               (security, network, compliance)  
          rds-investigate                      6-phase RDS instance             
                                               investigation (security,         
                                               network, compliance)             
          s3-investigate                       6-phase S3 bucket investigation  
                                               (public access, encryption,      
                                               compliance)                      
          workspaces-investigate               6-phase WorkSpaces               
                                               investigation (cost, security,   
                                               compliance)                      
          vpc-investigate                      6-phase VPC/TGW investigation    
                                               (topology, security, flow logs)  

πŸ’‘ Common Workflows:
  Quick discovery:    runbooks inventory resource-explorer --resource-type ec2 
--profile $AWS_PROFILE
  With cost data:     Add --enrich-costs --billing-profile BILLING
  Full 5-layer:       runbooks inventory workflow-multi-account

πŸ”‘ Profile Requirements:
  CENTRALISED_OPS: Resource Explorer aggregator access
  BILLING: Cost Explorer API access (enrich-costs)
  MANAGEMENT: Organizations API access (enrich-accounts)

SubcommandsΒΆ

Subcommand Description
check-cloudtrail-compliance β€”
check-controltower β€”
check-landingzone β€”
clean-outputs β€”
collect β€”
collect-analytics β€”
collect-containers β€”
collect-messaging β€”
collect-ram-shares β€”
cross-validate β€”
describe-delegated-admin-policy β€”
discover-lambda β€”
discover-rds β€”
draw-org β€”
drift-detection β€”
ebs-health β€”
ec2-investigate β€”
enrich β€”
enrich-accounts β€”
enrich-activity β€”
enrich-costs β€”
enrich-ec2 β€”
find-cfn-drift β€”
find-cfn-orphaned-stacks β€”
find-cfn-stackset-drift β€”
find-lz-versions β€”
list-app-registry-applications β€”
list-cfn-stacks β€”
list-cfn-stacksets β€”
list-delegated-administrators β€”
list-elbs β€”
list-enabled-services β€”
list-enis β€”
list-guardduty-detectors β€”
list-org-accounts β€”
list-org-policies β€”
list-org-users β€”
list-outputs β€”
list-resource-groups β€”
list-sns-topics β€”
org-governance-report β€”
pipeline-summary β€”
rds-investigate β€”
reconcile β€”
recover-cfn-stack-ids β€”
resource-explorer β€”
resource-types β€”
s3-investigate β€”
score-decommission β€”
show-profiles β€”
ssm-status β€”
tag-coverage β€”
validate-costs β€”
validate-mcp β€”
vpc β€”
vpc-investigate β€”
workflow-multi-account β€”
workflow-single-account β€”
workspaces-investigate β€”

OverviewΒΆ