scp-guardrails
AWS service control policy builder and linter.
What it is
scp-guardrails builds AWS Organizations service control policies from a short spec (region allowlist, protected roles, deny leaving the org, deny disabling CloudTrail and GuardDuty, deny root, require IMDSv2, deny public S3 ACLs, spend denies) under the SCP size limit, lints existing SCPs for the mistakes that lock you out or do nothing, and runs as a GitHub Action.
pipx install git+https://github.com/basitalisandhu/scp-guardrails
scp-guardrails build --spec examples/spec.yaml --out scps
scp-guardrails lint scps/
Install
pip install scp-guardrails # once published to PyPI
pipx install git+https://github.com/basitalisandhu/scp-guardrails # the scp-guardrails command, isolated
uvx --from git+https://github.com/basitalisandhu/scp-guardrails scp-guardrails --help # run without installing
From the README; see the full README for every option.
Links
Releases
Topics: aws, aws-organizations, aws-security, cli, cloud-security, devsecops, github-actions, guardrails, hacktoberfest, iam, landing-zone, linter, policy-as-code, python, sarif, scp, security-tools, service-control-policies