Offline, read-only comparison of two exported AWS IAM identity policy documents. It reports syntactic changes to Allow actions, resources, and simple equality constraints. It never computes effective permissions.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
node bin/iam-least-privilege-diff.mjs --root examples/pass --before before.json --after after.json
node bin/iam-least-privilege-diff.mjs --root examples/fail --before before.json --after after.json
npm run checkRead the result
The CLI emits one JSON report. Exit 0 means pass, 1 means fail, and 2 means incomplete or invalid CLI options. Invalid options or root produce no stdout. Input files are resolved by realpath within --root; escapes, unreadable named files, malformed JSON, duplicate decoded keys (including escaped spellings), and invalid UTF-8 yield incomplete. No files are written.
Where this check stops
Each file is at most 524,288 bytes; each policy at most 1,000 statements; each statement at most 1,000 actions, 1,000 resources, and 100 StringEquals keys/values; JSON depth at most 16; evaluation deadline 5,000 ms with an injectable monotonic clock. At N the boundary is accepted; N+1 yields incomplete. Output order is deterministic UTF-16 code-unit order. The tool does not evaluate groups, attached/inline combinations, permission boundaries, resource policies, service control policies, session policies, explicit-deny effects, principals, condition operators beyond StringEquals, policy variables, wildcard expansion, or live AWS state. Its effectivePermissions field is always not-evaluated; a pass only means no concerning change was found in this supported comparison.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.