Home / Security tooling

scp-guardrails

AWS service control policy builder and linter.

Python · MIT · latest v0.1.0

What it is

scp-guardrails builds AWS Organizations service control policies from a short spec (region allowlist, protected roles, deny leaving the org, deny disabling CloudTrail and GuardDuty, deny root, require IMDSv2, deny public S3 ACLs, spend denies) under the SCP size limit, lints existing SCPs for the mistakes that lock you out or do nothing, and runs as a GitHub Action.

pipx install git+https://github.com/basitalisandhu/scp-guardrails
scp-guardrails build --spec examples/spec.yaml --out scps
scp-guardrails lint scps/

Install

pip install scp-guardrails                                                              # once published to PyPI
pipx install git+https://github.com/basitalisandhu/scp-guardrails                        # the scp-guardrails command, isolated
uvx --from git+https://github.com/basitalisandhu/scp-guardrails scp-guardrails --help   # run without installing

From the README; see the full README for every option.

Releases

Topics: aws, aws-organizations, aws-security, cli, cloud-security, devsecops, github-actions, guardrails, hacktoberfest, iam, landing-zone, linter, policy-as-code, python, sarif, scp, security-tools, service-control-policies