Ross ROSS = Recommend OSS · open-source software intelligence for agents

cloud-custodian/cloud-custodian

Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources observed · 2026-08-28

github.com/cloud-custodian/cloud-custodian · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

90/100

  • Activity 99
  • Release rhythm 74
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 63.0
  • age_days: 3838
  • days_rel: 97
  • days_push: 7
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

6053 stars · 1644 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Cloud Custodian (c7n) is a Python-based stateless rules engine for managing public cloud accounts and resources via YAML policy DSLs with filters and actions. It enforces security, compliance, and cost-optimization policies across AWS, Azure, GCP, and other providers, running locally, on cron, or as provisioned serverless functions.

Use cases

  • enforce encryption and access compliance policies across cloud accounts
  • turn off EC2 instances and ASGs off-hours to save cost
  • garbage collect unused or untagged cloud resources
  • enforce tag compliance and mark non-compliant resources for remediation
  • run policy checks against terraform IaC in CI pipelines
  • real-time remediation of cloud security events via serverless functions
  • replace ad-hoc cloud management scripts with declarative policies

When to choose

  • you need unified governance, security, and cost management across AWS, Azure, and GCP
  • you want declarative YAML policies instead of maintaining custom cloud scripts
  • you need real-time enforcement via serverless event integration
  • you want compliance-as-code with dry-run, metrics, and structured reporting

When to avoid

  • you only use on-premises or non-cloud infrastructure
  • you need a full CSPM commercial product with dashboards and support
  • you prefer imperative configuration management tools like Ansible for host-level tasks

Facets

cli-tool · maturity stable

security configuration-management workflow-automation monitoring infrastructure-as-code cli scheduling webhook cloud-computing security infrastructure-as-code self-hosted python windows serverless cloud cloud-governance finops policy-as-code compliance-as-code yaml-dsl aws azure gcp cost-optimization cncf devops automation linux macos docker

10 sources

Member repositories

RepositoryRoleHealth v2
cloud-custodian/cloud-custodianmain90

For agents

markdown · JSON · MCP: product_card(name="cloud-custodian/cloud-custodian")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem