{"repo":"aws-cloudformation/cloudformation-guard","free":true,"listed":false,"github":"https://github.com/aws-cloudformation/cloudformation-guard","clone":"git clone https://github.com/aws-cloudformation/cloudformation-guard.git","description":"Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0","language":"Rust","stars":1385,"topics":["policy-as-code","cloudformation","terraform","k8s","policy-rule-evaluation","governance","security","compliance","cfn-guard"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"AWS CloudFormation Guard Validate Cloud Environments with Policy-as-Code AWS CloudFormation Guard is an open-source general-purpose policy-as-code evaluation tool. It provides developers with a simple-to-use, yet powerful and expressive domain-specific language (DSL) to define policies and enables developers to validate JSON- or YAML- formatted structured data with those policies. The Guard 3.0 release introduces support for stateful rules through built-in functions, SAM CLI as an alternative deployment method for cfn-guard-lambda , command auto-completions for shell, advanced regular expressions, improved handling of intrinsic functions for the test command, as well as the --structured flag to the validate command to emit JSON/YAML parseable output. Note that previously written tests may have to be reviewed due to the corrected behavior of intrinsic function handling. Please see the release notes for full details and examples. Guard can be used for the following domains: 1. Preventative Governance and Compliance (shift left): validate Infrastructure-as-code (IaC) or infrastructure/service compositions such as CloudFormation Templates, CloudFormation ChangeSets, Terraform JSON configuration files, Kubernetes configurations, and more against Guard policies representing your organizational best practices for security, compliance, and more. For example, developers can use Guard policies with 1. Terraform plan ( in JSON format ) for deployment safety assessment checks or Terrafor","default_branch":null,"files":null,"tree":[],"storefront":"/r/aws-cloudformation","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aws-cloudformation/cloudformation-guard/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}