EXTENSIONS
Built by operatives — models, drivers, vaults, and reports, the parts that plug into Swamp.
Filter by what you need and pull what fits.
Gcp/iam
Google Cloud iam infrastructure models
Aws/iam
AWS IAM infrastructure models
Zitadel
Zitadel for swamp, over its API: seven model types, one per resource, with the whole life cycle of each.
Versitygw
A versitygw S3 gateway for swamp, read over its admin API and its S3 API. Read-only.
Cloudflare/iam
Cloudflare iam infrastructure models
Aws/iam
Cross-account IAM observation model for role, user, and policy inventory.
Aws Access Key
Mint, inventory, deactivate and delete AWS IAM access keys — the step @swamp/aws/iam cannot model — delivering a new key straight into a named vault item, verified by read-back and rolled back if delivery fails
Gcp/iam
Bootstrap and maintain the GCP identities CI authenticates as: Workload Identity Federation pools and providers, the service accounts behind them, and the IAM bindings tying the two together. CI cannot create the identity it federates into, so an operator provisions it out of band with this model. Project IAM grants and revocations are condition-aware — including delegated role grants, which bound `roles/resourcemanager.projectIamAdmin` to a fixed set of roles — and policies are read and written at version 3 so conditional bindings survive a read-modify-write.
Twilio/iam
Twilio iam API models
Okta
Okta CIAM identity models
Aws Iam Role Audit
Read-only fleet IAM lens for an integration's roles across many accounts. A
Scaleway Iam
Manage a Scaleway IAM application — sync, create, update, delete, and list applications, plus list API-key metadata and policies, via the global IAM API (/iam/v1alpha1) with X-Auth-Token auth.
Fact Store Aurora Bootstrap
One-shot bootstrap for @twonines/fact-store backed by AWS Aurora Postgres Serverless v2. Provisions the RDS cluster + writer instance, the enclosing VPC networking primitives (DB subnet group, security group), an IAM managed policy scoped to rds-db:connect on the cluster, and an IAM workload role that trusts a caller-provided principal (e.g., an AWS SSO permission set ARN). A companion workflow runs the provisioner and then configures @webframp/postgres-datastore against the newly created cluster using a fresh RDS IAM auth token.
Aws Integration Coverage
Coalesces a CloudFormation StackSet lens (@jentz/aws-stackset-audit) and an
Zitadel
Careful, non-destructive administration of a Zitadel instance over its Management API (v1 REST), authenticated with a JWT private-key service account. Read/audit of orgs, projects, applications, users and managers; idempotent provisioning of OIDC/API applications and machine (service) users; project-role and user-grant authorization (roles, grants, and the role-assertion flag that surfaces roles in tokens); rotation of client secrets, PATs, machine keys and secrets; and reversible deactivate/reactivate. Machine identities only. The only hard delete is a single, verify-first project-role removal (roles have no deactivate state); secrets are emitted once and marked sensitive.