Open-source tool VIGIL enforces AWS access revocations in real time
A developer has released VIGIL, an open-source AWS access recertification engine, on the aws-samples GitHub organisation. Unlike traditional review tools that log decisions without acting on them, VIGIL applies access changes directly to live AWS resources at the moment a decision is made. The tool uses scoped, surgical modifications — such as removing a single permission for one user on one bucket — rather than broad policy detachments that could cause unintended outages. All decisions and changes are recorded in a hash-chained, append-only audit trail with optional WORM storage, and every change can be rolled back. VIGIL is fully serverless, currently supports S3, IAM, and EC2 connectors, and is designed to be extended to other AWS services with minimal effort.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in