Guide · IAM

See what an AWS IAM role can do

Effective permissions from your AWS profile, locally and read-only. Goku's IAM Lab connects to your real AWS account with a profile you already have, scans its roles, and shows for any role every action it is allowed and the policy statement behind it, who can assume it in plain words, and what is risky. Nothing in the account changes, and your credentials stay in memory.

Updated 30 September 2026 · Goku 4.2.0 · goku CLI 0.6.0 · Free

Goku was formerly called Mimir. Same product, new name: the image is now tanujsoni027/goku (it was tanujsoni027/mimir-aws) and the command is goku. See old and new names.

On this page: What you see · Read-only · Install · Connect · Pick a role · MCP · FAQ

Effective permissions

What you see for each role

A role's access is spread over its trust policy, managed and inline policies and permissions boundary. The IAM Lab puts it together, from a scan of the account:

An AWS IAM role in Goku's IAM Lab: administrator warning, allowed actions by access level, and S3 actions with their resources and condition keys
A role's access: a summary, allowed actions by access level, and each action with its resources and condition keys. The account shown is sample data.
Safe by design

Read-only, with your own profile

The profile needs IAM read access: the AWS managed policies IAMReadOnlyAccess, SecurityAudit or ReadOnlyAccess are enough.

Step 1

Install or update Goku

Role access needs Goku 4.2 and goku CLI 0.6.0 or later. On macOS and Linux:

terminal
$ curl -fsSL https://tanuj24.github.io/goku/install.sh | sh

On Windows, in PowerShell:

PowerShell
PS> irm https://tanuj24.github.io/goku/install.ps1 | iex

Already installed? Run goku update --cli, then goku update.

goku start mounts your AWS config folder read-only into Goku (~/.aws, or %USERPROFILE%\.aws on Windows, at /run/goku/aws), so the console can list your profiles. Files that AWS_CONFIG_FILE or AWS_SHARED_CREDENTIALS_FILE name elsewhere are mounted read-only too. goku update recreates an existing container to add the mount, and goku doctor shows whether it is there. GOKU_AWS_PROFILES=off leaves it out.

Running the image with plain Docker? Add the mount to your docker run:

terminal
$ mkdir -p ~/.goku/data
docker run -d --name goku \
  -p 8080:80 -p 4566:4566 -p 5500-5524:5500-5524 \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v ~/.goku/data:/app/data \
  -v /tmp/goku-glue:/tmp/goku-glue \
  -v ~/.aws:/run/goku/aws:ro \
  tanujsoni027/goku:latest

In PowerShell, the mount is -v "$env:USERPROFILE\.aws:/run/goku/aws:ro". The rest of the command is on the install page.

Step 2

Connect a profile

In the console

Open IAM in the console and choose Role access, http://localhost:8080/iam/roles. Your profiles are listed with their type and region; Connect scans the account's IAM (roles, users and policies) into a snapshot.

Role access in Goku's IAM Lab: connected AWS accounts and the AWS profiles of ~/.aws with access keys, SSO, assume-role and credential process types, read-only
Role access lists the profiles of your ~/.aws. A profile that needs your terminal shows the command to run.

From a terminal

terminal
$ goku iam profiles                 # type, region, SSO account and role; never keys
goku iam connect --profile prod   # sign in, connect read-only, scan
terminal
$ goku iam connect --profile prod
getting credentials for profile prod from the AWS CLI…
connecting profile prod to Goku (read-only)…
  ✔ profile credentials                   terminal session
  ✔ sts:GetCallerIdentity                 arn:aws:sts::123456789012:assumed-role/Admin/me
  ✔ iam:GetAccountAuthorizationDetails    allowed
  – iam:SimulatePrincipalPolicy           optional — AccessDenied: not allowed
Connected acme-prod (123456789012) with profile prod: 213 roles, 45 users, 1,204 policies.

goku iam connect takes the profile from --profile, else AWS_PROFILE, the only profile or default, or asks. It gets the profile's credentials on your machine with the AWS CLI (aws configure export-credentials), so SSO, MFA codes and credential helpers work, and it runs aws sso login first when an SSO sign-in has expired. Goku receives a session in the body of one request, never on a command line, on disk or on screen. Without the AWS CLI, only access-key profiles work.

No goku CLI at hand? Paste temporary credentials in the console takes the output of aws configure export-credentials --profile NAME --format env.

Step 3

Pick a role and see its access

The roles list shows who each role trusts, when it was last used and its policies, with filters for service roles, cross-account roles, federated (OIDC or SAML) roles and roles not used in 90 days. Service-linked roles are hidden unless you ask for them.

The roles of an AWS account in Goku's IAM Lab with who each role trusts, such as GitHub Actions OIDC, AWS Lambda or another account, when it was last used and its policies
The account's roles, with who each one trusts, when it was last used and its policies.
terminal
$ goku iam roles                                  # NAME, TRUSTED BY, LAST USED, POLICIES
goku iam roles deploy                           # search name, path, ARN or who it trusts
goku iam access ci-deployer                     # who can assume it, policies, access per service, risks
goku iam access ci-deployer --service s3,iam    # and its S3 and IAM actions
goku iam access ci-deployer --all --json > ci-deployer.json
goku iam access ci-deployer --open              # the role in the console

--profile NAME or --connection ID picks the account; the default is the profile you scanned most recently. The answers come from the scan, not from new calls to AWS, so rescan from the roles list, or run goku iam connect again, to see changes made since. In the console, Export saves a role's access as JSON, Markdown or CSV.

Who can assume an AWS IAM role, in plain words: a GitHub Actions OIDC provider limited to one repository, and another AWS account that must pass an external ID
Who can assume the role, in plain words, with each condition of its trust policy and the statement it comes from.
AI assistants

Ask your AI assistant

Goku's MCP server has four tools for the roles of your AWS account:

Profiles and connectgoku_iam_aws_profiles goku_iam_connect_aws_profileYour AWS profiles, never their keys, and a read-only connection and scan of one account.
Roles and accessgoku_iam_aws_roles goku_iam_role_accessThe account's roles and who they trust, and everything one role can do. Both read Goku's scan, not AWS.

When a profile needs you, for an SSO sign-in or an MFA code, the tool says which command to run in your terminal. Ask, for example:

FAQ

Frequently asked questions

Does Goku change anything in my AWS account?

No. Every AWS call Goku makes with a profile passes a read-only guard: only reads such as sts:GetCallerIdentity and IAM Get, List and Simulate operations can be sent, and anything else fails before it is signed, even when the profile is an administrator.

Where are my AWS credentials kept?

In Goku's memory, only until they expire. They are never saved, logged or returned by any API. Your ~/.aws folder is mounted read-only, and only the IAM Lab reads it.

Which AWS profiles work?

Access keys, IAM Identity Center (SSO) and assume-role profiles. Profiles that need your terminal, such as an MFA code, a credential helper or an expired SSO sign-in, connect with goku iam connect --profile NAME.

What permissions does the profile need?

IAM read access. The AWS managed policies IAMReadOnlyAccess, SecurityAudit or ReadOnlyAccess are enough.

How do I keep Goku from seeing my ~/.aws folder?

Set GOKU_AWS_PROFILES=off for the goku CLI and it doesn't mount the folder. With plain Docker, leave out the -v ~/.aws:/run/goku/aws:ro mount.