#!/usr/bin/env bash # --------------------------------------------------------------------------- # Collects the AWS resource identifiers this project needs (AGENTS.md Q10). # Read-only: no call creates or mutates anything. # # chmod +x scripts/aws-discover.sh # ./scripts/aws-discover.sh > aws-inventory.txt # # aws-inventory.txt contains NO secrets — only resource names and IDs — so it # is safe to share. It is gitignored anyway. # --------------------------------------------------------------------------- set -uo pipefail hr() { printf '\n== %s %s\n' "$1" "$(printf '=%.0s' $(seq 1 $((60 - ${#1}))))"; } try() { "$@" 2>&1 || echo " (failed — check permissions or region)"; } command -v aws >/dev/null || { echo "AWS CLI not installed. See docs/reference/AWS-Hosting-Guide.md Part 0.5"; exit 1; } hr "Identity and default region" try aws sts get-caller-identity --output table echo "default region: $(aws configure get region || echo '(unset)')" hr "S3 buckets -> which one holds the site?" try aws s3 ls hr "CloudFront distributions -> Id, Aliases, Origin" try aws cloudfront list-distributions \ --query "DistributionList.Items[].{Id:Id,Status:Status,Domain:DomainName,Aliases:join(',',Aliases.Items||[\`none\`]),Origin:Origins.Items[0].DomainName}" \ --output table hr "ACM certificates (us-east-1 — CloudFront certs live there)" try aws acm list-certificates --region us-east-1 \ --query "CertificateSummaryList[].{Domain:DomainName,Status:Status,Arn:CertificateArn}" --output table hr "API Gateway HTTP APIs -> the intake endpoint" try aws apigatewayv2 get-apis \ --query "Items[].{Name:Name,ApiId:ApiId,Endpoint:ApiEndpoint,Protocol:ProtocolType}" --output table hr "Lambda functions" try aws lambda list-functions \ --query "Functions[].{Name:FunctionName,Runtime:Runtime,Modified:LastModified}" --output table hr "DynamoDB tables" try aws dynamodb list-tables --output table hr "SES verified identities" try aws sesv2 list-email-identities \ --query "EmailIdentities[].{Identity:IdentityName,Type:IdentityType,Verified:VerifiedForSendingStatus}" --output table hr "S3 versioning on each bucket (rollback depends on this)" for b in $(aws s3api list-buckets --query 'Buckets[].Name' --output text 2>/dev/null); do printf ' %-45s %s\n' "$b" "$(aws s3api get-bucket-versioning --bucket "$b" --query 'Status' --output text 2>/dev/null || echo '?')" done hr "Done" cat <<'NOTE' Send back: * the S3 bucket that holds the site * the CloudFront distribution Id whose Aliases include adr.smlcompany.ca * the default region, and the region of the DynamoDB table * the API Gateway Endpoint for the intake API NOTE