aws-iam v5.49.0 - Track and manage SSH Public Keys in CMDB
Aug 13, 2026•GuardrailsMods
Guardrails can now discover IAM user SSH public keys (the AWS CodeCommit credential type) as a new AWS > IAM > SSH Public Key resource type under each AWS > IAM > User. Track keys and their status in the CMDB in real time, alarm on or delete inactive and aged keys with the Active control, and govern whether SSH public keys are permitted with the Allowed controls.
Resource Types
Added
- AWS > IAM > SSH Public Key
Control Types
Added
- AWS > IAM > SSH Public Key > Active
- AWS > IAM > SSH Public Key > Allowed
- AWS > IAM > SSH Public Key > Allowed > Custom
- AWS > IAM > SSH Public Key > CMDB
- AWS > IAM > SSH Public Key > Discovery
Policy Types
Added
- AWS > IAM > SSH Public Key > Active
- AWS > IAM > SSH Public Key > Active > Age
- AWS > IAM > SSH Public Key > Active > Status
- AWS > IAM > SSH Public Key > Allowed
- AWS > IAM > SSH Public Key > Allowed > Custom
- AWS > IAM > SSH Public Key > Allowed > Custom > Rules
- AWS > IAM > SSH Public Key > CMDB
Action Types
Added
- AWS > IAM > SSH Public Key > Delete
- AWS > IAM > SSH Public Key > Delete from AWS
- AWS > IAM > SSH Public Key > Router
- AWS > IAM > SSH Public Key > Skip alarm for Active control
- AWS > IAM > SSH Public Key > Skip alarm for Active control [90 days]