policy-as-code

There are 240 repositories under policy-as-code topic.

  • opal

    permitio/opal

    Policy and data administration, distribution, and real-time updates on top of Policy Agents (OPA, Cedar, ...)

    Language:Python5.4k30167243
  • octelium/octelium

    A next-gen FOSS self-hosted unified zero trust secure access platform that can operate as a remote access VPN, a ZTNA platform, API/AI/MCP gateway, a PaaS, an ngrok-alternative and a homelab infrastructure.

    Language:Go2.6k13977
  • fixinventory

    someengineering/fixinventory

    Fix Inventory helps you identify and remove the most critical risks in AWS, GCP, Azure and Kubernetes.

    Language:Python2k21164135
  • kptdev/kpt

    Automate Kubernetes Configuration Editing

    Language:Go1.8k391.9k240
  • aws-cloudformation/cloudformation-guard

    Guard offers a policy-as-code domain-specific language (DSL) to write rules and validate JSON- and YAML-formatted data such as CloudFormation Templates, K8s configurations, and Terraform JSON plans/configurations against those rules. Take this survey to provide feedback about cfn-guard: https://amazonmr.au1.qualtrics.com/jfe/form/SV_bpyzpfoYGGuuUl0

    Language:Rust1.4k40233189
  • pacbot

    tmobile/pacbot

    PacBot (Policy as Code Bot)

    Language:Java1.3k79197281
  • open-policy-agent/awesome-opa

    A curated list of OPA related tools, frameworks and articles

  • vet

    safedep/vet

    Protect against malicious open source packages 🤖

    Language:Go8251520368
  • mobility-data-specification

    openmobilityfoundation/mobility-data-specification

    A data specification to enable right-of-way regulation, digital policy, geofencing, and two-way communication between mobility companies and public agencies worldwide.

  • opengovern/opensecurity

    opensecurity: open-source security and compliance. See and secure your cloud, containers, code, networks, deployments, devices. Define your rules, get precise checks, fix gaps fast. Streamlined audits. No fluff.

    Language:TypeScript61723412
  • selefra/selefra

    The open-source policy-as-code software that provides analysis for Multi-Cloud and SaaS environments, you can get insight with natural language (powered by OpenAI).

    Language:Go54151445
  • awesome-azure-policy

    globalbao/awesome-azure-policy

    A curated list of blogs, videos, tutorials, code, tools, scripts, and anything useful to help you learn Azure Policy - by @JesseLoudon

  • regal

    open-policy-agent/regal

    Regal is a linter and language server for Rego, bringing your policy development experience to the next level!

    Language:Go3451060648
  • mondoohq/cnspec

    An open source, cloud-native security to protect everything from build to runtime

    Language:Go3231328419
  • noqdev/iambic

    IAMbic is Version-Control for IAM. It centralizes and simplifies cloud access and permissions. It maintains an eventually consistent, human-readable, bi-directional representation of IAM in Git.

    Language:Python29679427
  • microsoft/regorus

    Regorus - A fast, lightweight Rego (OPA policy language) interpreter written in Rust.

    Language:Rust240511745
  • kubewarden/kubewarden-controller

    Manage admission policies in your Kubernetes cluster with ease

    Language:Go217749738
  • hysnsec/awesome-policy-as-code

    A curated list of policy-as-code resources like blogs, videos, and tools to practice on for learning Policy-as-Code.

  • stakpak/devx

    A tool for generating, validating & sharing all your configurations, powered by CUE. Works with Kubernetes, Terraform, Compose, GitHub actions and much more...

    Language:Go1935159
  • globalbao/azure-policy-as-code

    Bicep and Terraform code examples for policy-as-code workflows. Azure governance guardrails and automation - by @JesseLoudon

    Language:HCL183191082
  • permitio/cedar-agent

    Cedar-agent is the easiest way to deploy and run Cedar

    Language:Rust17641418
  • anderseknert/kube-review

    Create Kubernetes AdmissionReview requests from Kubernetes resource manifests

    Language:Go161366
  • kubewarden/policy-server

    Webhook server that evaluates WebAssembly policies to validate Kubernetes requests

    Language:Rust151618020
  • magtape

    tmobile/magtape

    MagTape Policy-as-Code for Kubernetes

    Language:Python151125729
  • aipotheosis-labs/gate22

    Open-source MCP gateway and control plane for teams to govern which tools agents can use, what they can do, and how it’s audited—across agentic IDEs like Cursor, or other agents and AI tools.

    Language:TypeScript14014
  • aws-cloudformation/aws-guard-rules-registry

    Rules Registry for Compliance Frameworks

    Language:Python1341219328
  • gjyoung1974/soc2-policy-templates

    Template SOC2 Policy Authority - documentation pipeline

    Language:HTML1338038
  • open-policy-agent/vscode-opa

    An extension for VS Code which provides support for OPA and the Rego policy language

    Language:TypeScript12387431
  • chef/cookstyle

    A linting tool that helps you to write better Chef Infra cookbooks and InSpec profiles by detecting and automatically correcting style, syntax, and logic mistakes in your code.

    Language:Ruby1132934559
  • hexa-org/policy-orchestrator

    Hexa Policy Orchestrator enables you to manage all of your access policies consistently across software providers.

    Language:Shell103826816
  • augur-ai/mantis

    Mantis is a unified infrastructure as code framework that replaces Terraform and Helm

    Language:Go100511
  • kubewarden/kwctl

    Go-to CLI tool for Kubewarden users

    Language:Rust86816623
  • intercept

    xfhg/intercept

    INTERCEPT / Policy as Code Auditing & Compliance

    Language:Go857219
  • dod-advana/gamechanger

    GAMECHANGER aspires to be the Department’s trusted solution for evidence-based, data-driven decision-making across the universe of DoD requirements

    Language:Shell7516524
  • developer-guy/policy-as-code-war

    OPA Gatekeeper vs Kyverno