Skip to main content

EXTENSIONS

Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.

Filter by what you need and pull what fits.

Selection
15 results
label:iam

Gcp/iam

@swamp/gcp/iam · v2026.10.06.1

Google Cloud iam infrastructure models

upd Oct 6432 pullsA100/100

Aws/iam

@swamp/aws/iam · v2026.10.06.1

AWS IAM infrastructure models

upd Oct 691k pullsA100/100

Zitadel

@dataverket/zitadel · v2026.10.05.1

Zitadel for swamp, over its API: seven model types, one per resource, with the whole life cycle of each.

upd Oct 521 pullsA100/100

Versitygw

@dataverket/versitygw · v2026.10.05.1

A versitygw S3 gateway for swamp, read over its admin API and its S3 API. Read-only.

upd Oct 517 pullsA100/100

Cloudflare/iam

@swamp/cloudflare/iam · v2026.09.29.2

Cloudflare iam infrastructure models

upd Sep 2919 pullsA100/100

Aws/iam

@webframp/aws/iam · v2026.09.24.1

Cross-account IAM observation model for role, user, and policy inventory.

upd Sep 2522 pullsA100/100

Aws Access Key

@sntxrr/aws-access-key · v2026.09.23.2

Mint, inventory, deactivate and delete AWS IAM access keys — the step @swamp/aws/iam cannot model — delivering a new key straight into a named vault item, verified by read-back and rolled back if delivery fails

upd Sep 2328 pullsA100/100

Gcp/iam

@hivemq/gcp/iam · v2026.09.11.1789122862

Bootstrap and maintain the GCP identities CI authenticates as: Workload Identity Federation pools and providers, the service accounts behind them, and the IAM bindings tying the two together. CI cannot create the identity it federates into, so an operator provisions it out of band with this model. Project IAM grants and revocations are condition-aware — including delegated role grants, which bound `roles/resourcemanager.projectIamAdmin` to a fixed set of roles — and policies are read and written at version 3 so conditional bindings survive a read-modify-write.

upd Sep 1154 pullsB85/100

Twilio/iam

@keeb/twilio/iam · v2026.08.25.2

Twilio iam API models

upd Aug 2614 pullsB85/100

Okta

@keeb/okta · v2026.08.25.3

Okta CIAM identity models

upd Aug 2521 pullsB85/100

Aws Iam Role Audit

@jentz/aws-iam-role-audit · v2026.07.20.1

Read-only fleet IAM lens for an integration's roles across many accounts. A

upd Jul 2019 pullsA100/100

Scaleway Iam

@sntxrr/scaleway-iam · v2026.07.19.1

Manage a Scaleway IAM application — sync, create, update, delete, and list applications, plus list API-key metadata and policies, via the global IAM API (/iam/v1alpha1) with X-Auth-Token auth.

upd Jul 1914 pullsA100/100

Fact Store Aurora Bootstrap

@twonines/fact-store-aurora-bootstrap · v2026.07.17.8

One-shot bootstrap for @twonines/fact-store backed by AWS Aurora Postgres Serverless v2. Provisions the RDS cluster + writer instance, the enclosing VPC networking primitives (DB subnet group, security group), an IAM managed policy scoped to rds-db:connect on the cluster, and an IAM workload role that trusts a caller-provided principal (e.g., an AWS SSO permission set ARN). A companion workflow runs the provisioner and then configures @webframp/postgres-datastore against the newly created cluster using a fresh RDS IAM auth token.

upd Jul 1824 pullsA100/100

Aws Integration Coverage

@jentz/aws-integration-coverage · v2026.06.26.1

Coalesces a CloudFormation StackSet lens (@jentz/aws-stackset-audit) and an

upd Jun 2716 pullsA100/100

Zitadel

@thomas/zitadel · v2026.06.24.1

Careful, non-destructive administration of a Zitadel instance over its Management API (v1 REST), authenticated with a JWT private-key service account. Read/audit of orgs, projects, applications, users and managers; idempotent provisioning of OIDC/API applications and machine (service) users; project-role and user-grant authorization (roles, grants, and the role-assertion flag that surfaces roles in tokens); rotation of client secrets, PATs, machine keys and secrets; and reversible deactivate/reactivate. Machine identities only. The only hard delete is a single, verify-first project-role removal (roles have no deactivate state); secrets are emitted once and marked sensitive.

upd Jun 2419 pullsA100/100