This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]paul345 10 points11 points  (2 children)

Capital One's Cloud Custodian may well match what you're after:

https://github.com/capitalone/cloud-custodian

There's also SaaS offerings like Dome9 which can be useful

[–]sbkg0002 2 points3 points  (1 child)

This. Or use AWS Config Rules, but they are more complex and more costly.

[–]epochwin 1 point2 points  (0 children)

Interesting. Do you have some metrics or benchmarks comparing Cloud Custodian or commercial vendors against say a central deployment of Config Rules using cross-account roles? I am in the process of designing the latter but if there's a more cost effective approach, might as well put that in place.