aws-iam v5.49.0 - Track and manage SSH Public Keys in CMDB

Aug 13, 2026GuardrailsMods

Guardrails can now discover IAM user SSH public keys (the AWS CodeCommit credential type) as a new AWS > IAM > SSH Public Key resource type under each AWS > IAM > User. Track keys and their status in the CMDB in real time, alarm on or delete inactive and aged keys with the Active control, and govern whether SSH public keys are permitted with the Allowed controls.

Resource Types

Added

  • AWS > IAM > SSH Public Key

Control Types

Added

  • AWS > IAM > SSH Public Key > Active
  • AWS > IAM > SSH Public Key > Allowed
  • AWS > IAM > SSH Public Key > Allowed > Custom
  • AWS > IAM > SSH Public Key > CMDB
  • AWS > IAM > SSH Public Key > Discovery

Policy Types

Added

  • AWS > IAM > SSH Public Key > Active
  • AWS > IAM > SSH Public Key > Active > Age
  • AWS > IAM > SSH Public Key > Active > Status
  • AWS > IAM > SSH Public Key > Allowed
  • AWS > IAM > SSH Public Key > Allowed > Custom
  • AWS > IAM > SSH Public Key > Allowed > Custom > Rules
  • AWS > IAM > SSH Public Key > CMDB

Action Types

Added

  • AWS > IAM > SSH Public Key > Delete
  • AWS > IAM > SSH Public Key > Delete from AWS
  • AWS > IAM > SSH Public Key > Router
  • AWS > IAM > SSH Public Key > Skip alarm for Active control
  • AWS > IAM > SSH Public Key > Skip alarm for Active control [90 days]