🗂️ Navigation

CloudFormation Guard

A policy-as-code tool for CloudFormation.

Visit Website →

Overview

CloudFormation Guard is an open-source command-line interface (CLI) that provides a policy-as-code language to define rules that can check for both required and prohibited resource configurations. It enables developers to validate their CloudFormation templates against those rules.

✨ Key Features

  • Policy-as-code for CloudFormation
  • Declarative language for writing rules
  • Validation of CloudFormation templates
  • Integration with CI/CD pipelines
  • Can be used to validate any JSON- or YAML-formatted data

🎯 Key Differentiators

  • Developed and supported by AWS
  • Deep integration with the AWS CloudFormation ecosystem
  • Purpose-built for validating CloudFormation templates

Unique Value: Provides a simple and effective way to enforce policies on your CloudFormation templates.

🎯 Use Cases (3)

Enforcing security policies for CloudFormation templates Ensuring compliance with organizational standards Preventing misconfigurations in AWS resources

✅ Best For

  • Requiring encryption on all S3 buckets
  • Ensuring that all EC2 instances are launched in a specific VPC

💡 Check With Vendor

Verify these considerations match your specific requirements:

  • Checking IaC for other platforms like Terraform or Kubernetes

🏆 Alternatives

Checkov Terrascan

Easier to use for CloudFormation-specific policies than more general-purpose tools.

💻 Platforms

CLI

✅ Offline Mode Available

🔌 Integrations

AWS CloudFormation CI/CD pipelines

🛟 Support Options

  • ✓ Live Chat

💰 Pricing

Contact for pricing
Free Tier Available

Free tier: Open source and free to use.

Visit CloudFormation Guard Website →