A read-only census of every managed database your AWS credentials can reach.
Runs on your machine, output stays local, zero telemetry.
How it works
Uses the standard AWS credential chain: env vars, profiles, SSO. Read-only IAM permissions, describe and list calls only. Nothing is ever modified.
Sweeps RDS, Aurora, DocumentDB, Neptune, DynamoDB, ElastiCache, and Redshift across every region, or your whole AWS Organization with --org.
One self-contained HTML file, plus JSON and CSV. Scans archive on your machine, so the next run shows exactly what changed.
See the sprawl
A sample of the HTML report. Engine versions checked against end-of-life dates, ownership scored from tags, scan failures listed, never hidden.
Built for DBAs, not dashboards
Runs from your laptop against your own credentials. No agents, no CloudFormation, nothing installed in the target account.
Reports are written to disk and scan history stays in ~/.blueprint. No analytics, no crash reporting, no update checks. The only network calls are to AWS.
Maps what is reachable from the credentials you give it. Owner and environment come from tags, imported and never inferred, and every scan failure is listed in the report.
Need this mapped, governed, and access-controlled centrally?
hoop turns discovery into control. Centralize access to every database it finds, with policy, data masking, and full audit logs.