turbot/aws_compliance

Query: iam_role_unused_60

Usage

powerpipe query aws_compliance.query.iam_role_unused_60

Steampipe Tables

SQL

select
arn as resource,
case
when role_last_used_date <= (current_date - interval '60' day)
or role_last_used_date is null then 'alarm'
else 'ok'
end as status,
case
when role_last_used_date is null then name || ' was never used.'
else name || ' was last used ' || to_char(role_last_used_date, 'DD-Mon-YYYY') || ' (' || extract(
day
from
current_date - role_last_used_date
) || ' days ago).'
end as reason,
account_id
from
aws_iam_role;

Controls

The query is being used by the following controls: