IAM Policy Autopilot now supports Terraform plan files
Share
Services
IAM Policy Autopilot can now generate baseline IAM policies directly from a Terraform plan file. IAM Policy Autopilot is an open source tool, launched at re:Invent 2025, that analyzes your code to deterministically create scoped-down IAM policies you can refine as your application evolves, reducing the time you spend writing IAM policies and troubleshooting access issues. Until now the tool analyzed application source code, but it was not possible to generate policies for deploying AWS infrastructure defined via Infrastructure as Code. Now you can pass a Terraform plan file as input, and IAM Policy Autopilot applies a deterministic analysis to produce a policy scoped to the CRUD functions of the resources in that plan. The generated policies reference specific resource ARNs rather than wildcards, when possible. Supporting policy generation for deploying AWS infrastructure defined via Terraform has been the most requested capability since IAM Policy Autopilot launched, and it complements the existing Terraform-aware analysis, which cross-references Terraform resource definitions with SDK calls in your application code to resolve ARNs. IAM Policy Autopilot is available at no additional cost and runs on your own machine. To get started, visit the [IAM Policy Autopilot GitHub repository](https://github.com/awslabs/iam-policy-autopilot).
What else is happening at Amazon Web Services?
New AWS experience helps builders get started and ship faster
about 19 hours ago
Services
Share
Read update
Services
Share
Amazon Connect Customer can now import evaluation form PDFs using AI
about 20 hours ago
Services
Share
Amazon WorkSpaces adds support for NVIDIA Blackwell GPU instances
about 20 hours ago
Services
Share
AWS Elemental MediaTailor Monetization Functions adds ad response hooks
about 20 hours ago
Services
Share