npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@codyswann/aws-soc2-setup

v1.1.2

Published

Automated AWS Control Tower setup for SOC 2 compliance — account provisioning, IAM Identity Center, security services, backup, and KMS as a typed CLI

Downloads

26

Readme

AWS Control Tower SOC 2 Automation Suite

License: MIT npm SOC 2 aligned AWS Control Tower

Open-source TypeScript CLI for SOC 2–aligned AWS Control Tower environments

aws-soc2-setup turns the usual multi-day Control Tower + SOC 2 bootstrap into a guided, skip-friendly workflow: Identity Center, organizational units, security services, controls, backup, KMS, and root lockdown.

New here? Durable project knowledge lives in the LLM Wiki. Browse wiki/index.md or run /onboard-me (Codex: $lisa-wiki-onboard-me).

Table of contents

Overview

This package is a typed Node.js CLI (aws-soc2-setup) published as @codyswann/aws-soc2-setup. It uses AWS SDK v3 under the hood and replaces the earlier Bash suite with the same domain coverage:

| Domain | What it covers | | --- | --- | | setup | 16-step orchestrator (plan + automatable steps) | | status / whoami | Environment readiness and caller identity | | sso | IAM Identity Center users, groups, assignments, profile config | | controltower | OUs, Account Factory provisioning, Control Tower controls | | security | GuardDuty, Security Hub, Config, Macie, Inspector, Audit Manager | | backup | AWS Backup vault/plan + delegated admin | | kms | Key administrators and rotation | | root | Delete root access keys; org-wide root credential removal | | scp | Deny long-lived IAM credentials org-wide; management-account creation alerts |

Manual console steps (root MFA, enabling Identity Center, landing zone creation) stay explicit in the plan — the CLI does not pretend those are fully automatable.

Features

  • Guided setupsetup prints the ordered plan and runs the automatable steps
  • Dry-run safe — global --dry-run previews mutating work; status is always read-only
  • Multi-account architecture — management, audit, log archive, and workload accounts via Control Tower
  • IAM Identity Center — users, groups, and permission-set assignment instead of long-lived IAM users
  • SOC 2–oriented controls — security services, Control Tower guardrails, backup, and KMS
  • Root protection — delete root keys and remove root credentials from member accounts
  • Open source — MIT licensed; contributions welcome

Install

Requirements: Node.js 18+, AWS credentials (CLI profile or default chain), and an AWS account where you can enable Organizations / Control Tower.

# one-shot
npx @codyswann/aws-soc2-setup --help

# or install globally
npm install -g @codyswann/aws-soc2-setup
aws-soc2-setup --help

From a clone of this repo (Bun is the package manager):

git clone https://github.com/CodySwannGT/aws-soc2-setup.git
cd aws-soc2-setup
bun install
bun run build
./bin/aws-soc2-setup.js --help

Quick start

# Confirm credentials
aws-soc2-setup whoami -p your-admin-profile

# See what the environment already has
aws-soc2-setup status -p your-admin-profile

# Preview the full setup plan (no changes)
aws-soc2-setup setup --dry-run -p your-admin-profile

# Run automatable steps (OUs, security services, optional controls/backup/audit)
aws-soc2-setup setup -p your-admin-profile \
  --ou ou-xxxx-xxxxxxxx \
  --central-account 111122223333 \
  --admin-account 444455556666 \
  --audit-account 777788889999

Global options (apply to every command):

| Flag | Description | | --- | --- | | -p, --profile <profile> | AWS CLI profile | | -r, --region <region> | Region (default: AWS_REGION or us-east-1) | | --dry-run | Preview mutating actions without applying them | | -y, --yes | Skip confirmation prompts (required for destructive root ops) |

Commands

| Command | Purpose | | --- | --- | | status | Read-only readiness: credentials, Organizations, recommended OUs, Identity Center, member accounts | | whoami | Print STS caller identity | | setup | Print the 21-step plan and run automatable steps | | sso create-user / group / assign | Identity Center users, groups, permission sets | | sso configure-profile / set-start-url | Local SSO profile and start URL | | controltower create-organization | Create AWS Organizations (FeatureSet=ALL) if missing | | controltower create-ous | Create Infrastructure / Workloads / Sandbox OUs | | controltower register-ou | Register an OU with Control Tower (EnableBaseline) | | controltower provision-account | Account Factory provisioning (--wait supported) | | controltower enable-controls | Enable Control Tower controls for an OU | | security enable | Enable GuardDuty, Security Hub, Config, Macie, Inspector | | security audit | Config aggregator (+ Audit Manager only if already enabled; unavailable for new accounts after 2026-04-30) | | security conformance-packs | Deploy AWS Config sample Conformance Packs (CIS / WA Security / CT detective) | | backup | Configure AWS Backup (vault, plan, delegated admin) | | kms | Manage key administrators and rotation | | root delete-keys / remove-access | Root key deletion and org-wide root lockdown (--yes required) | | scp deny-iam-users | SCP denying IAM user / access key / login profile creation, attached to the org root or given OUs (--yes required; --exempt-arn for break-glass) | | scp alert-management | EventBridge → SNS email alert on IAM credential creation — detective coverage for the management account, which SCPs cannot bind (--yes required; run in us-east-1) |

Run aws-soc2-setup <command> --help for flags on each subcommand.

Setup plan

setup follows this sequence. Automated steps run when you invoke setup (with the options they need); manual steps are printed as guidance.

| # | Step | Kind | | --- | --- | --- | | 1 | Initial AWS CLI / SSO profile setup | Manual (sso configure-profile) | | 2 | Enable MFA for the root user | Manual (console) | | 3 | Create AWS Organizations | Automated (controltower create-organization) | | 4 | Enable IAM Identity Center | Manual (console) | | 5 | Set up AWS Control Tower landing zone | Manual (console) | | 6 | Create the admin user | Manual (sso create-user, sso assign, root delete-keys) | | 7 | Create the initial users group | Manual (sso group) | | 8 | Create additional users | Manual (sso create-user / sso group) | | 9 | Create organizational units | Automated (controltower create-ous --all) | | 10 | Register OUs with Control Tower | Automated (controltower register-ou) | | 11 | Enable security services | Automated (security enable --all) | | 12 | Enable Control Tower controls | Automated (controltower enable-controls) | | 13 | Configure AWS Backup | Automated (backup) | | 14 | Configure audit and reporting | Automated (security audit) | | 15 | Deploy Config Conformance Packs | Automated (security conformance-packs --preset recommended) | | 16 | Provision additional accounts | Manual (controltower provision-account) | | 17 | Custom Identity Center domain | Manual (sso set-start-url) | | 18 | Disable root access for sub-accounts | Manual (root remove-access --yes) | | 19 | Configure KMS key management | Manual (kms) | | 20 | Block long-lived IAM credentials | Manual (scp deny-iam-users --yes) | | 21 | Alert on management-account IAM credential creation | Manual (scp alert-management -e <email> --yes) |

Track progress with docs/CHECKLIST.md.

Security considerations

  • Root access keys may be created temporarily during bootstrap; delete them promptly (root delete-keys). If a run is interrupted, remove any leftover root keys manually.
  • The management account is exempt from SCPs by AWS designscp deny-iam-users protects every member account, but cannot prevent IAM user creation in the management account itself. Pair it with scp alert-management (detection) and keep workloads out of the management account.
  • root remove-access is destructive and requires --yes. Review member accounts before running it.
  • New Account Factory accounts do not automatically inherit every security service. Re-run security enable (or setup) after provisioning.
  • Least privilege — prefer Identity Center permission sets over long-lived IAM users; review cross-account roles regularly.
  • This tool helps implement technical controls relevant to SOC 2. It does not guarantee a successful audit.

Development

bun install
bun run build
bun run test
bun run lint
bun run typecheck

Source lives under src/ (commands, domain modules, shared lib/). Tests mirror that layout under tests/ (Vitest + aws-sdk-client-mock).

Contributing

Contributions are welcome — see CONTRIBUTING.md. Open issues and pull requests against CodySwannGT/aws-soc2-setup.

License

MIT — see LICENSE.

Disclaimer

This suite helps implement technical controls relevant to SOC 2 compliance but does not guarantee a successful audit. Work with qualified auditors for your organization's specific requirements.