-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathcor.yaml
More file actions
80 lines (62 loc) · 2.03 KB
/
Copy pathcor.yaml
File metadata and controls
80 lines (62 loc) · 2.03 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
#
# Example COR config file.
#
# By default COR reads from: $HOME/.cor.yaml
# You can override via: cor --config /path/to/cor.yaml <command>
#
# ---- Global options (match CLI flag names) ----
region: us-east-1
profile: default
auth-method: AWS_CREDENTIALS_FILE # or: ENV_SECRET
# Danger zone: enabling delete here means `--delete` default becomes true unless overridden.
delete: false
# Sorting buffers output in memory (disables streaming).
sort-by: "" # e.g. "Name"
sort-desc: false
# ---- Command-specific options (optional) ----
filter-by-name: "" # used by several commands (volumes/images/snapshots/enis/elasticips/...)
# images:
creation-date-before: "" # YYYY-MM-DD
creation-date-after: "" # YYYY-MM-DD
include-used-by-instance: false
include-used-by-launch-template: false
# natgateways:
filter-by-state: available
# targetgroups:
include-attached: false
# autoscaling:
force: false
# rds:
include-instances: true
include-snapshots: true
# efs:
# include-attached: false
# ecr:
untagged-only: true
older-than-days: ""
# route53:
include-non-empty: false
# vpcendpoints:
filter-by-service: ""
# include-attached: false
include-non-interface: false
# clientvpn:
include-active: false
# vpnconnections:
filter-by-id: ""
include-up: false
# tgwattachments:
filter-by-resource: ""
include-associated: false
include-non-vpc: false
# iamroles:
# filter-by-name: "" # substring/glob on role name
path-prefix: "" # e.g. /application/ (empty = all roles)
max-unused-days: 90 # never-used roles must also be at least this old
include-empty: false # also flag roles with no attached/inline policies and no instance profile
require-tag: "" # safety allowlist: only touch roles with ALL these tags (key or key=value, comma-separated)
# iampolicies:
# path-prefix: "" # e.g. /service-role/
min-age-days: 0 # only report policies created at least this many days ago
# include-attached # shared flat key, set once above (targetgroups); also applies here
# require-tag: "" # safety allowlist (same syntax as iamroles); uses iam:ListPolicyTags