cloudformation-guard
Config checker
An evaluation tool for policy-as-code in infrastructure configuration files
Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0
1k stars
40 watching
182 forks
Language: Rust
last commit: almost 2 years agocfn-guardcloudformationcompliancegovernancek8spolicy-as-codepolicy-rule-evaluationsecurityterraform
Related projects:
| Repository | Description | Stars |
|---|---|---|
| A tool to validate Terraform IAM policies against AWS best practices and security standards. | 299 | |
| A tool for validating AWS CloudFormation templates and improving the work experience with CloudFormation. | 92 | |
| A tool that scans AWS IAM policies to identify security vulnerabilities and generates a report with recommendations for remediation | 2,009 | |
| Automatically generates AWS Service Control Policies based on compliance frameworks and custom service inclusions/exclusions | 224 | |
| Identifies and protects insecure configurations in AWS resources across multiple accounts. | 437 | |
| Generates and manages least privilege IAM policies using an external audit service | 29 | |
| Automates cloud infrastructure monitoring and optimization by analyzing Terraform state files and detecting drifts, security risks, and cost estimation. | 224 | |
| Tools to analyze and report on AWS IAM policies for security best practices | 119 | |
| Generates AWS CloudFormation templates from Dhall expressions | 30 | |
| A CloudWatch Events rule Lambda function that checks security group permissions against a pre-configured policy and logs non-compliant changes. | 25 | |
| Converts an IAM Policy in JSON format into a Terraform aws_iam_policy_document | 781 | |
| Checks AWS accounts for subdomain hijacking vulnerabilities | 84 | |
| A Python library to create and manage AWS Access Policy Language JSON | 395 | |
| Automated CloudFormation template generation and deployment tool for AWS Lambda functions and serverless projects. | 46 | |
| A tool for managing public cloud accounts and resources by enforcing security policies and cost optimization through a simple rules engine. | 5,488 |