CLI Command Index¶
Browse 128 runbooks CLI commands by operational phase, cloud provider, service category, or persona.
By Operational Phase (F2T2EA)¶
| Phase | What You're Doing | CLI Groups |
|---|---|---|
| Find | Discovering what exists | inventory, cert, vpc |
| Fix | Correlating and enriching | inventory enrich-* |
| Track | Monitoring trends over time | finops dashboards, cost tracking |
| Target | Selecting resources for action | decommission scoring, optimize-* |
| Engage | Executing operations | operate, remediation |
| Assess | Evaluating posture | security, cfat, validation |
By Cloud Provider¶
| Provider | Commands | Groups |
|---|---|---|
| AWS | 121 | All 9 groups |
| Azure | 5 | finops azure * |
| Multi-Cloud | 2 | cert inventory, cert triage |
By Service Category¶
| Category | Commands | Use When |
|---|---|---|
| Cost Management (23) | dashboard, cost-drops, optimize-* | Monthly reviews, savings hunts |
| Management (48) | collect, list-org, draw-org | Organization discovery |
| Networking (20) | vpc topology, nat-traffic, list-elbs | Network troubleshooting |
| Security/Identity (13) | assess, baseline, cert inventory | Compliance audits |
| Compute (10) | analyze-ec2, graviton, lambda | Right-sizing |
| Storage (5) | s3-lifecycle, ec2-snapshots | Storage optimization |
| End User Computing (5) | analyze-workspaces, appstream | EUC cost analysis |
| Databases (2) | detect-rds-idle | Database optimization |
| App Integration (2) | collect-messaging, list-sns-topics | Messaging discovery |
By Persona¶
| Role | What They Need | Start Here |
|---|---|---|
| CFO | Budget compliance, cost trends | finops dashboard, cert report |
| CTO | Architecture health, drift detection | cfat assess, inventory vpc topology |
| SRE | Anomaly detection, operations | finops cost-drops, operate |
| Architect | Cross-cutting analysis | inventory collect, security assess |
All Tags¶
Color Legend
Tags are color-coded by dimension: F2T2EA Phase | Cloud Provider | Service Category | Persona
Cloud Foundation¶
Cloud-Foundation¶
- Cloud Foundation: 29 Capabilities across 6 Categories
- Finance Management & FinOps
- [Cloud-Foundation] Trackers and Planning Templates
- devops.oceansoft.io
CloudOps¶
- Accelerating Speed, Efficiency, and Cloud Maturity
- Home
- Site Reliability Engineering (SRE) & CloudOps Runbooks Automation
- Site Reliability Engineering (SRE) & CloudOps Runbooks Automation
- The Cloud Foundations Quick Start Pack
- The Production-Ready Python Template for Scalable Projects 🌟
DevOps¶
- Accelerating Speed, Efficiency, and Cloud Maturity
- Home
- The Production-Ready Python Template for Scalable Projects 🌟
Digital-Transformation¶
Docker/K8s¶
FinOps¶
- Accelerating Speed, Efficiency, and Cloud Maturity
- Home
- The Production-Ready Python Template for Scalable Projects 🌟
Foundation¶
Generative-AI¶
Infrastructure¶
- Cloud Foundation: 29 Capabilities across 6 Categories
- [Cloud-Foundation] Trackers and Planning Templates
Runbooks¶
- Cloud Assets Inventory using AWS Resource Explorer & Q Developer
- [CloudOps Runbooks] Security Baseline Assessment
Security¶
Solution¶
architecture¶
assessment¶
category-cost management¶
category-cost-management¶
- Analyze ec2
- Analyze s3 storage lens
- Analyze workspaces
- Azure anomaly
- Azure daily
- Azure dashboard
- Azure monthly
- Azure preflight
- Azure validate
- Check config compliance
- Cost drops
- Dashboard
- Detect orphans
- Detect rds idle
- Ebs
- Ec2 decommission analysis
- Ec2 snapshots
- Enrich workspaces
- Export
- Infrastructure
- Lambda analysis
- Optimize
- Optimize cloudwatch costs
- Optimize s3 lifecycle
- Optimize savings plans
- S3 crossvalidate
- S3 noncurrent sizing
- S3 storage class recommend
- Workspaces decommission analysis
category-management¶
- 4-Profile AWS Credential Contract
- B2B-Energy Tenant Evidence Pack
- CLI Reference — Multi-Account LZ Discovery
- CSDM & Tagging
- CSDM-First Tag Taxonomy v2.0
- Cert status
- Check
- Check cloudtrail compliance
- Check controltower
- Check landingzone
- Clean outputs
- Cloud Foundations Assessment
- CloudOps Platform
- Cloudformation deploy
- Collect
- Collect analytics
- Collect containers
- Collect messaging
- Collect ram shares
- Common Utilities
- Cross validate
- Dashboard
- Data Validation
- Describe delegated admin policy
- Discover lambda
- Discover rds
- Draw org
- Drift detection
- Dual-Mode Invocation Matrix
- Ebs health
- Ec2 investigate
- Ec2 start
- Ec2 stop
- Enrich accounts
- Enrich activity
- Enrich costs
- Enrich ec2
- Find cfn drift
- Find cfn orphaned stacks
- Find cfn stackset drift
- Find lz versions
- Gate
- ITSM Integration
- Info
- Info
- Info
- Inventory & Discovery
- List app registry applications
- List cfn stacks
- List cfn stacksets
- List delegated administrators
- List elbs
- List enabled services
- List enis
- List guardduty detectors
- List org accounts
- List org policies
- List org users
- List resource groups
- List sns topics
- MCP Integration
- Multi-Account Landing Zone
- Operational Readiness
- Org governance report
- Pipeline summary
- Rds investigate
- Recover cfn stack ids
- Resource Operations
- Resource explorer
- Resource types
- S3 create bucket
- S3 investigate
- SCP, Tag, Backup, and AI Services Policy Overview
- Scope
- Score decommission
- Ssm status
- Stage1 starter
- Tag coverage
- Tag fill rate
- Tag schema validate
- Tag validate
- Validate 5way
- Validate costs
- Validate mcp
- Vpc create vpc
- Vpc dependencies
- Vpc flow logs
- Vpc investigate
- Vpc nat traffic
- Vpc security groups
- Vpc validate
- WorkSpaces Optimization
- Workflow multi account
- Workflow single account
- Workspaces
category-networking¶
category-security-identity¶
- AWS Permission Requirements for Runbooks CLI
- Baseline
- Certificate Management
- Certificate Management SOP
- S3 compliance check
- Security & Compliance
- Security Remediation
cloud-aws¶
- 4-Profile AWS Credential Contract
- AWS Permission Requirements for Runbooks CLI
- Account Assessment
- B2B-Energy Tenant Evidence Pack
- CLI Reference — Multi-Account LZ Discovery
- CSDM & Tagging
- CSDM-First Tag Taxonomy v2.0
- Certificate Management
- Certificate Management SOP
- Cloud Foundations (AWS Solutions)
- Cloud Foundations Assessment
- CloudOps Platform
- Common Utilities
- CxO Dashboard — AWS Organizations
- Data Validation
- Dual-Mode Invocation Matrix
- FinOps & Cost Optimization
- ITSM Integration
- Inventory & Discovery
- Landing Zone Accelerator
- MCP Integration
- Multi-Account Landing Zone
- Network & Connectivity
- Network Orchestration (Transit Gateway)
- Operational Readiness
- Overview
- Resource Operations
- SCP, Tag, Backup, and AI Services Policy Overview
- Security & Compliance
- Security Remediation
- WorkSpaces Optimization
- Workload Discovery
cloud-azure¶
cloud-multi-cloud¶
cloud-security¶
cmdb¶
compliance¶
cost¶
discovery¶
f2t2ea-assess¶
- Baseline
- Cert status
- Certificate Management SOP
- Cloud Foundations Assessment
- Data Validation
- S3 compliance check
- Security & Compliance
- Tag schema validate
- Tag validate
- Validate 5way
f2t2ea-engage¶
- Cloudformation deploy
- Ec2 start
- Ec2 stop
- Resource Operations
- S3 create bucket
- Scope
- Security Remediation
- Vpc create vpc
f2t2ea-find¶
- CSDM & Tagging
- Certificate Management
- Certificate Management SOP
- Check
- Check cloudtrail compliance
- Check controltower
- Check landingzone
- Clean outputs
- CloudOps Platform
- Collect
- Collect analytics
- Collect containers
- Collect messaging
- Collect ram shares
- Common Utilities
- Cross validate
- Dashboard
- Describe delegated admin policy
- Discover lambda
- Discover rds
- Draw org
- Drift detection
- Ebs health
- Ec2 investigate
- Enrich accounts
- Enrich activity
- Enrich costs
- Enrich ec2
- Find cfn drift
- Find cfn orphaned stacks
- Find cfn stackset drift
- Find lz versions
- Gate
- ITSM Integration
- Info
- Info
- Info
- Inventory & Discovery
- List app registry applications
- List cfn stacks
- List cfn stacksets
- List delegated administrators
- List elbs
- List enabled services
- List enis
- List guardduty detectors
- List org accounts
- List org policies
- List org users
- List resource groups
- List sns topics
- MCP Integration
- Network & Connectivity
- Operational Readiness
- Org governance report
- Pipeline summary
- Rds investigate
- Recover cfn stack ids
- Resource explorer
- Resource types
- S3 investigate
- Score decommission
- Ssm status
- Stage1 starter
- Tag coverage
- Tag fill rate
- Tgw diagram
- Tgw discover
- Tgw hub binding
- Tgw hybrid
- Tgw routes
- Validate costs
- Validate mcp
- Vpc dependencies
- Vpc flow logs
- Vpc investigate
- Vpc nat traffic
- Vpc security groups
- Vpc validate
- Vpce cleanup
- WorkSpaces Optimization
- Workflow multi account
- Workflow single account
- Workspaces
f2t2ea-track¶
- Analyze ec2
- Analyze s3 storage lens
- Analyze workspaces
- Azure anomaly
- Azure daily
- Azure dashboard
- Azure monthly
- Azure preflight
- Azure validate
- Check config compliance
- Cost drops
- Dashboard
- Detect orphans
- Detect rds idle
- Ebs
- Ec2 decommission analysis
- Ec2 snapshots
- Enrich workspaces
- Export
- FinOps & Cost Optimization
- Infrastructure
- Lambda analysis
- Optimize
- Optimize cloudwatch costs
- Optimize s3 lifecycle
- Optimize savings plans
- S3 crossvalidate
- S3 noncurrent sizing
- S3 storage class recommend
- Workspaces decommission analysis
finops¶
governance¶
inventory¶
lza¶
multi-account¶
network¶
organization¶
organizations¶
permissions-iam¶
persona-architect¶
- 4-Profile AWS Credential Contract
- AWS Permission Requirements for Runbooks CLI
- B2B-Energy Tenant Evidence Pack
- CSDM-First Tag Taxonomy v2.0
- Certificate Management
- Certificate Management SOP
- Cloud Foundations Assessment
- Dual-Mode Invocation Matrix
- FinOps & Cost Optimization
- Inventory & Discovery
- Multi-Account Landing Zone
- Network & Connectivity
- SCP, Tag, Backup, and AI Services Policy Overview
- Security & Compliance
- Tgw diagram
- Tgw discover
- Tgw hub binding
- Tgw hybrid
- Tgw routes
- Vpce cleanup
persona-cfo¶
persona-cio¶
persona-ciso¶
persona-cto¶
- B2B-Energy Tenant Evidence Pack
- CSDM-First Tag Taxonomy v2.0
- Certificate Management SOP
- CxO Dashboard — AWS Organizations
- Multi-Account Landing Zone
persona-cxo¶
- Analyze ec2
- Analyze s3 storage lens
- Analyze workspaces
- Azure anomaly
- Azure daily
- Azure dashboard
- Azure monthly
- Azure preflight
- Azure validate
- Check config compliance
- Cloud Foundations Assessment
- Cost drops
- Dashboard
- Detect orphans
- Detect rds idle
- Ebs
- Ec2 decommission analysis
- Ec2 snapshots
- Enrich workspaces
- Export
- FinOps & Cost Optimization
- Infrastructure
- Lambda analysis
- Optimize
- Optimize cloudwatch costs
- Optimize s3 lifecycle
- Optimize savings plans
- S3 crossvalidate
- S3 noncurrent sizing
- S3 storage class recommend
- Security & Compliance
- Workspaces decommission analysis
persona-developer¶
persona-securityengineer¶
persona-sre¶
- 4-Profile AWS Credential Contract
- CLI Reference — Multi-Account LZ Discovery
- Cert status
- Certificate Management
- Certificate Management SOP
- Check
- Check cloudtrail compliance
- Check controltower
- Check landingzone
- Clean outputs
- Cloudformation deploy
- Collect
- Collect analytics
- Collect containers
- Collect messaging
- Collect ram shares
- Cross validate
- Dashboard
- Data Validation
- Describe delegated admin policy
- Discover lambda
- Discover rds
- Draw org
- Drift detection
- Dual-Mode Invocation Matrix
- Ebs health
- Ec2 investigate
- Ec2 start
- Ec2 stop
- Enrich accounts
- Enrich activity
- Enrich costs
- Enrich ec2
- FinOps & Cost Optimization
- Find cfn drift
- Find cfn orphaned stacks
- Find cfn stackset drift
- Find lz versions
- Gate
- Info
- Info
- Info
- Inventory & Discovery
- List app registry applications
- List cfn stacks
- List cfn stacksets
- List delegated administrators
- List elbs
- List enabled services
- List enis
- List guardduty detectors
- List org accounts
- List org policies
- List org users
- List resource groups
- List sns topics
- Multi-Account Landing Zone
- Network & Connectivity
- Org governance report
- Pipeline summary
- Rds investigate
- Recover cfn stack ids
- Resource Operations
- Resource explorer
- Resource types
- S3 create bucket
- S3 investigate
- SCP, Tag, Backup, and AI Services Policy Overview
- Scope
- Score decommission
- Security Remediation
- Ssm status
- Stage1 starter
- Tag coverage
- Tag fill rate
- Tag schema validate
- Tag validate
- Validate 5way
- Validate costs
- Validate mcp
- Vpc create vpc
- Vpc dependencies
- Vpc flow logs
- Vpc investigate
- Vpc nat traffic
- Vpc security groups
- Vpc validate
- Workflow multi account
- Workflow single account
- Workspaces