Back to the project in the portfolio

wasteless.io

Nothing is written to the AWS account until a human opens the door: collection runs through a read-only role, simulation is the default mode, and a real write requires a second opt-in role.

Internal step External service Checkpoint — review or opt-in Verified output Application boundary
Schedule / CLI wasteless.io · self-hosted (Docker) 1 · Detection Collection boto3 · Steampipe 9 detector families EC2 · RDS · EBS · EIP… Recommendations evidence · confidence · €/mo AWS account read-only IAM role inventory PostgreSQL inventory + recs reads FastAPI + UI recommendation review simulation by default 2 · Execution & verification Action plan dry-run by default Direct AWS action write role · opt-in Terraform pull request Git review Manual task backlog Verification real state after action AWS Cost Explorer saving confirmed at day 7
Waste is detected with a read-only role; writing only exists on the amber path, behind a second opt-in IAM role. The other two paths leave the tool (Git, backlog) and come back through the verification step. A saving is only declared once seven days of billing have gone by.
PythonFastAPIAWSboto3SteampipeTerraformDockerPostgreSQL
View the code

All architecture diagrams