Skip to main content

Preflight

Preflight is a command-line tool that audits your AWS account and tells you what's worth fixing. It looks at how you deploy, what you're spending, and how much of your infrastructure depends on one or two people, then writes up a report you can share with the rest of your team.

It's read-only and open source (Apache-2.0), and it runs on your own machine. Your AWS credentials stay there.

We're Jet1, a managed DevOps team for startups that haven't hired a DevOps engineer yet. Preflight is the audit we run on every first call, packaged so you can run it yourself.

Getting started

Install it:

curl -fsSL https://jetonecloud.com/preflight | sh

You can also install it with pipx, brew, or Docker (see docs/installation.md). If you don't have the AWS CLI set up locally, you can run it from AWS CloudShell instead.

To see what a report looks like before pointing it at your account:

preflight demo

When you're ready to scan for real:

  1. Pick what you want checked and generate the role it needs:
preflight scan --modules cost --save

Run preflight scan on its own and it'll ask instead: first which checks to run, then which permissions to grant them. Every service the checks need starts selected, and you can switch any of them off with the arrow keys — --services ec2,rds does the same thing without the questions. Either way you get a CloudFormation template granting only the read-only actions those checks declare — nothing for the modules you didn't pick. This step makes no AWS calls and needs no credentials, so you can read the whole template before anything touches your account. (iam/role.cfn.yaml is the same thing with every module selected.)

  1. Deploy the template from the CloudFormation console, or with aws cloudformation deploy. The stack's RoleArn output is what you pass back to Preflight.
  2. Log in to AWS the way you usually do (aws sso login, a named profile, and so on). Preflight won't ask you for access keys.
  3. Run the scan with the role ARN from the stack's outputs:
preflight scan --role-arn arn:aws:iam::123456789012:role/PreflightReadOnlyRole --region us-east-1

Before it starts, Preflight lists what it's going to read. When it's done, you'll have an HTML report and a JSON export saved locally.

If you'd rather not create the role, you can scan with an existing profile:

preflight scan --profile my-profile --region us-east-1

Preflight checks whether that identity has write or admin access and will warn you if it does. We'd still recommend the dedicated role.

Permissions and your data

The IAM policy in iam/policy.json only uses Get, List, and Describe actions, with no wildcards. Each module declares the actions it needs, so the role Preflight generates covers the checks you picked and nothing else — preflight scan --list-modules shows what each one asks for, and the permission picker lets you cut it down further by service. Nothing with a write verb or a wildcard can reach a generated policy; Preflight refuses to emit one.

Preflight uses the standard AWS credential chain (profiles, SSO, STS, assume-role). It never handles your keys directly and never sends credentials anywhere.

By default, nothing leaves your machine. The one exception is opt-in: you can ask us to email you a copy of the report. If you do, Preflight sends a summary of scores and findings over HTTPS, optionally with account IDs and resource names redacted, after you confirm your email address with a magic link. Run preflight preview first to see exactly what would be sent. Raw API responses are never sent or stored.

The dollar figures in the report are estimates. We keep them on the conservative side, and each one shows how it was worked out.

Releases are signed and come with checksums, so you can verify what you're running. SECURITY.md has the full details on data handling and our threat model.

Contributing

Contributions are welcome. Have a look at CONTRIBUTING.md and our CODE_OF_CONDUCT.md first.

License

Apache License 2.0, see LICENSE. Some of the check logic is adapted from other Apache-2.0 and MIT-licensed projects, and they're credited in NOTICE.

Want help fixing what it finds?

That's what we do at Jet1: deploys, AWS infrastructure, cost work, and on-call, with an SLA, and you own everything we build. If you'd like to talk it through with an engineer, book a 20-minute call.

Metadata

Release files for preflight-cli 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for preflight-cli 0.1.0
File Size Uploaded
preflight_cli-0.1.0.tar.gz 44.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for preflight-cli 0.1.0
File Interpreter ABI Platform
preflight_cli-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 72.4 kB

Release files / preflight_cli-0.1.0.tar.gz

Download URL preflight_cli-0.1.0.tar.gz
Size 44.2 kB
Tags Source
SHA-256 checksum
How to use checksums
863515a94328f34adb423ba0245fc4e3ee374c0987021a7fb825d0e594671006
BLAKE2b-256 checksum
How to use checksums
63f8c49dd2e8a56085eeb0164c2ac393a4e5025a3c7b7f9f836cd1d8dfcab40f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release files / preflight_cli-0.1.0-py3-none-any.whl

Download URL preflight_cli-0.1.0-py3-none-any.whl
Size 28.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cf73bf3183480703d8ab7710bc2d82915ab069a770507e49945e1ac975f8b98c
BLAKE2b-256 checksum
How to use checksums
d9fdd4632fb31ea88a8030607822780e328f9de7ff1f5510e7dfe5d91fcb3868
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 4, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page