Omahub
← All plugins
C

AWS Console

by cd

Amazon Web Services console for Lightsail, S3, Route 53, EC2, Lambda, CloudWatch, and FinOps billing.

Security review

Potentially dangerous behavior detected · 3 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
8f6d5f7
Scanned
1 month ago
  • high destructive_filesystem tests/test_aws_monitor.py:130

    Destructive operation on the root filesystem or a block device.

    rm -rf /", "us-east-1\n", "../../etc",
  • high destructive_filesystem tests/test_aws_monitor.py:451

    Destructive operation on the root filesystem or a block device.

    rm -rf /", "123456789012")
  • Docs external_hosts README.md:94

    Downloads or connects to an external HTTP(S) host.

    git clone https://github.com/craigderington/omarchy-aws.git ~/.config/omarchy/plugins/cd.aws

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
8f6d5f7
Reviewed
1 month ago

The plugin is a read-only AWS monitoring widget with optional user-initiated instance actions. The deterministic scan's high-severity findings are false positives: they are string literals in unit tests that verify input validation rejects malicious payloads, not actual commands. The medium finding is a standard installation instruction in the README. The code uses subprocess with argument lists (no shell), validates all inputs, and has no destructive behavior.

  • The deterministic scan flagged test strings containing 'rm -rf /' and similar, but these are only used to assert that validation rejects them; they are never executed.
  • The plugin can start/stop/reboot AWS instances if the user has the necessary IAM permissions, which could incur costs or disrupt services, but this is explicit user-initiated functionality and requires confirmation in the UI.
  • The README includes a git clone command for manual installation, which is standard and not a security issue.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/craigderington/omarchy-aws --enable
Developer Tools #quickshell

Omarchy AWS Console

Your Amazon Web Services infrastructure, directly in the Omarchy bar.

Omarchy AWS Console is a fast, keyboard-friendly command center for monitoring Lightsail virtual servers, S3 storage buckets, Route 53 DNS hosted zones, EC2 compute instances, serverless Lambda functions, CloudWatch alarms, and Month-to-Date FinOps spend—without keeping AWS Console browser tabs open.

Omarchy AWS Console preview


Features

Amazon Lightsail Virtual Servers

  • Real-time instance states (running, stopped, pending, stopping)
  • Hardware specs and OS blueprints (e.g. Debian, Ubuntu, CPU counts, RAM, and SSD disk sizes)
  • One-Click Actions:
    • Start, stop, or reboot Lightsail instances
    • Direct SSH Terminal Connect (ssh user@public-ip) launched into your native Omarchy terminal
    • Instant copy of Public / Private IPs to clipboard
    • Direct deep-links to the Lightsail Web Console

S3 Object Storage

  • Browse all S3 buckets with creation timestamps
  • Instant search and filtering across bucket catalogues
  • One-click copy of s3:// URIs
  • Direct links to browse buckets in the AWS Web Console

s3api list-buckets is a global call and does not report per-bucket regions, so none is shown rather than guessing from the selected region.

Route 53 DNS Management

  • Browse all hosted zones and domain registrations
  • View record set counts and zone IDs
  • One-click copy of Hosted Zone IDs
  • Direct links to manage record sets in Route 53 Web Console

EC2 Compute Management

  • Real-time instance states, instance types (t3.medium, c6i.xlarge), and public/private IPs
  • Start, stop, or reboot instances with instant UI state updates
  • Connect via AWS Systems Manager (SSM) Session Manager directly in your Omarchy terminal

Lambda Serverless Functions

  • Track active functions, runtimes (python3.12, nodejs20.x, go, etc.), allocated memory, and execution timeouts
  • Quick copy of Function ARNs and direct console links

CloudWatch Alarms and Proactive Alerts

  • Monitor metric alarms across services (EC2 CPU, ELB 5XX errors, ElastiCache memory, Lambda throttles)
  • Visual state badges (ALARM urgent red, OK green, INSUFFICIENT_DATA dim)
  • Native desktop notifications via notify-send when an alarm enters ALARM state

FinOps and Billing Tracking

  • Live Month-to-Date (MTD) spend, and an end-of-month projection prorated from the observed daily burn (MTD ÷ days elapsed × days in month)
  • Top AWS services ranked by cost (Registrar, Lightsail, Route 53, EC2, S3, RDS, NAT Gateways, etc.)
  • Direct shortcut to AWS Cost Management Console

Multi-Profile and Multi-Region Support

  • Discovers AWS profiles configured in ~/.aws/config and ~/.aws/credentials
  • Profile and region dropdowns in the panel header; switching either re-queries
  • An unknown profile is reported as an error rather than silently substituted

Demo Mode

  • Toggle Demo Mode in the footer to render synthetic sample data and make no AWS calls at all. Useful offline, for screenshots, and for trying the widget out.
  • Sample data uses reserved documentation values only (account 123456789012, RFC 5737 192.0.2.0/24 addresses, RFC 2606 example.* domains).
  • If credentials are missing or expired the backend falls back to the same sample data, but the panel says so explicitly in a red banner and the bar icon goes urgent — the fallback never silently masquerades as your real account, and it clears itself as soon as credentials work again.

Requirements

  • Omarchy with Quickshell status bar support
  • AWS CLI v2 (aws on PATH)
  • Python 3.10+ (python3 on PATH)
  • wl-copy (Wayland clipboard utility, included in Omarchy)
  • A Nerd Font (e.g. JetBrainsMono Nerd Font, included in Omarchy)

Installation

Method 1: Install via Omarchy CLI

omarchy plugin add https://github.com/craigderington/omarchy-aws.git --enable

Method 2: Manual / Local Installation

# Clone or copy into your Omarchy plugins directory
git clone https://github.com/craigderington/omarchy-aws.git ~/.config/omarchy/plugins/cd.aws

# Validate plugin manifest
omarchy plugin validate ~/.config/omarchy/plugins/cd.aws

# Enable the widget in your bar
omarchy plugin enable cd.aws right

Keyboard Shortcuts

Key Action
1 Switch to Lightsail tab
2 Switch to S3 Buckets tab
3 Switch to Route 53 tab
4 Switch to EC2 Instances tab
5 Switch to Lambda Functions tab
6 Switch to CloudWatch Alarms tab
7 Switch to Billing & Cost tab
R Trigger background data refresh
/ Focus the search field
Esc Clear the search, else close the panel

While the search field has focus every key goes to it, including the digits and h/j/k/l/r/x.


Bar Mouse Controls

  • Left Click: Open / Close AWS Console popup panel
  • Middle Click: Force immediate data refresh

Configuration

In ~/.config/omarchy/shell.json:

{
  "plugins": {
    "cd.aws": {
      "refreshIntervalSec": 120,
      "idleRefreshIntervalSec": 900
    }
  }
}
Setting Default Meaning
refreshIntervalSec 120 Polling frequency while the panel is open
idleRefreshIntervalSec 900 Polling frequency while the panel is closed, when only the bar badge and alarm notifications need to stay current. Clamped to at least refreshIntervalSec.

Required IAM permissions

Read-only display needs sts:GetCallerIdentity, lightsail:GetInstances, ec2:DescribeInstances, s3:ListAllMyBuckets, lambda:ListFunctions, route53:ListHostedZones, cloudwatch:DescribeAlarms and ce:GetCostAndUsage. Any of these that is denied is reported per-service in the panel rather than rendered as an empty list. The start/stop/reboot buttons additionally need the matching lightsail:*Instance / ec2:*Instances actions.


Development

The backend and the panel's JS helpers have unit tests, both fully offline and dependency-free (no AWS credentials, no aws binary, no npm install needed):

# Backend: 71 tests over parsing, validation, action dispatch and CLI safety
python3 -m unittest discover -s tests

# Model.js: panel formatting/filter/alarm-transition logic
node --test tests/model.test.mjs

License

MIT License © 2026 cd