$npx skillfedfor your agent

c7n

Cloud Custodian - Policy Rules Engine

Worth itPyPI Distributed ComputingReleased May 20262.0M downloads / moApache-2.0Pure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — c7n-0.9.51-py3-none-any.whl
v0.9.51 · released 2026-05-28 · Python <4.0.0,>=3.10.2 · 8 runtime deps: argcomplete, boto3, cryptography, jsonschema, python-dateutil, pyyaml, tabulate, urllib3

Yes. Cloud Custodian is actively maintained, has no known vulnerabilities, installs with low friction, and is widely used (top 5000 PyPI packages). It's a mature CNCF Incubating project with permissive licensing suitable for enterprise use. Install it if you need to automate cloud compliance, security, or cost management across AWS, Azure, or GCP at scale.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10.2 or later; cloud provider credentials (AWS, Azure, or GCP) must be configured in environment or local config.
  • Low install friction with 8 common runtime dependencies.
  • Active maintenance with recent commits and regular releases; last release 78 days ago.

License · maintenance · safety

Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for enterprise adoption.

last release 2026-05-28 (78 days) · last repo commit 2026-08-14 · 6,043 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 2,047,247 downloads/mo, #3,343 on PyPI

Verify before relying

pip install c7n

echo 'policies:
  - name: example
    resource: aws.s3
    filters:
      - type: cross-account
    actions:
      - type: remove-statements
        statement_ids: matched' > policy.yml

custodian run --dryrun -s output policy.yml
  • Specific number of supported AWS, Azure, and GCP resource types and available filters/actions.
  • Performance characteristics when running against large existing fleets or multi-account environments.
  • Serverless provisioning details and supported event sources beyond those mentioned.
  • Whether infrastructure-as-code validation works offline or requires cloud provider API access.
Same gist for agents: .md · .json

What it is and what it does

Cloud Custodian is a policy engine that lets you define cloud infrastructure rules in simple YAML files and enforce them across AWS, Azure, and GCP. You write policies specifying resource types (like EC2 instances or S3 buckets), filters to match resources, and actions to take on them—then run them on-demand, via cron, or as serverless functions triggered by cloud events. It consolidates ad-hoc cloud management scripts into a unified tool with built-in compliance checking, cost optimization, tagging enforcement, and real-time policy execution.

The package depends on boto3 for AWS, standard libraries like cryptography, jsonschema, and pyyaml for configuration parsing, and tabulate for output formatting. It's designed for teams managing large cloud fleets who need repeatable, auditable policy enforcement without writing custom code for each rule. Policies can run in dry-run mode first to preview what they would do, and results are stored in cloud-native object storage for reporting.

Use it for

  • Enforce security compliance by automatically terminating EC2 instances with unencrypted volumes or removing cross-account S3 bucket access.
  • Manage costs by scheduling unused resources for deletion or stopping instances outside business hours across multiple accounts.
  • Validate infrastructure-as-code (Terraform, etc.) policies on developer workstations or in CI pipelines before deployment.
  • Apply consistent tagging policies across resources and stop instances that don't meet tag compliance requirements.
  • Monitor and report on resource compliance in real-time by integrating with CloudWatch Events, Config Rules, or cloud provider audit logs.
  • Automate garbage collection of orphaned or temporary resources across large existing cloud fleets.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Cloud Custodian is actively maintained, has no known vulnerabilities, installs with low friction, and is widely used (top 5000 PyPI packages). It's a mature CNCF Incubating project with permissive licensing suitable for enterprise use. Install it if you need to automate cloud compliance, security, or cost management across AWS, Azure, or GCP at scale.

Install

c7n on PyPI

Before you install

Low install friction with 8 common runtime dependencies. Active maintenance with recent commits and regular releases; last release 78 days ago. Supports current Python versions (3.10.2+).

Requires Python 3.10.2 or later; cloud provider credentials (AWS, Azure, or GCP) must be configured in environment or local config.

License in practice

Apache-2.0 permissive license allows commercial and private use with minimal restrictions; suitable for enterprise adoption.

Quickstart

pip install c7n

echo 'policies:
  - name: example
    resource: aws.s3
    filters:
      - type: cross-account
    actions:
      - type: remove-statements
        statement_ids: matched' > policy.yml

custodian run --dryrun -s output policy.yml

Verify before relying

  • Specific number of supported AWS, Azure, and GCP resource types and available filters/actions.
  • Performance characteristics when running against large existing fleets or multi-account environments.
  • Serverless provisioning details and supported event sources beyond those mentioned.
  • Whether infrastructure-as-code validation works offline or requires cloud provider API access.

Package facts

LicenseApache-2.0 permissive
Python supportSupports the current Python release <4.0.0,>=3.10.2
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
argcompleteboto3cryptographyjsonschemapython-dateutilpyyamltabulateurllib3
MaintenanceActively maintained 78 days since the last release
Last repo commit
First released
Downloads2,047,247 / month, #3,343 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: Apache Software LicenseTopic :: System :: Distributed ComputingTopic :: System :: Systems Administration

Evidence: c7n-0.9.51-py3-none-any.whl

Tags

Capabilities
cloud policy enforcement enginemulti-cloud compliance automationaws azure gcp policy managementinfrastructure as code policy validationcloud resource compliance rulesserverless policy executioncloud security policy automation
Topics
cloud-compliancepolicy-automationmulti-cloud

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “cloud policy enforcement engine”

  • c7nCloud Custodian is a rules engine that enforces cloud infrastructure…
  • oslo.policyoslo.policy enforces role-based access control (RBAC) policies across…
  • c7n-azureAn Azure plugin for Cloud Custodian that automates policy-driven…

Give your agent the search over MCP, or paste the wish link into any chat.

More Distributed Computing packages

grpcio Worth it
PyPI · Distributed Computing · released Jul 2026

gRPC Python is an HTTP/2-based RPC framework that enables you to define and call remote procedures across network boundaries using protocol buffers for serialization.

Install it if you need RPC communication in a distributed system or are integrating with existing gRPC services.

Apache-2.0compiled wheel · 3.10+
446.4Mdownloads / mo
execnet With conditions
PyPI · Libraries · released Nov 2025

execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.

However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…

MITpure Python · 3.8+aging
172.1Mdownloads / mo
cloudpickle Worth it
PyPI · Scientific/Engineering · released Nov 2025

Cloudpickle extends Python's standard pickle module to serialize lambda functions, interactively-defined functions and classes, and other constructs that the default pickle cannot handle, making it suitable for cluster computing and remote code execution.

Install it if you need to serialize lambda functions, interactively-defined code, or non-standard Python constructs for cluster computing or distributed execution.

BSD-3-Clausepure Python · 3.8+
148.4Mdownloads / mo
smart-open Worth it
PyPI · Distributed Computing · released Jul 2026

Provides a unified, open()-compatible Python API for streaming large files from remote storage (S3, GCS, Azure, HDFS, SFTP, HTTP) and local filesystems, with transparent compression support.

Install it if you work with large files on cloud storage or remote systems and want to avoid writing boilerplate around multiple SDKs.

MITpure Python
72.8Mdownloads / mo
portalocker Worth it
PyPI · Libraries · released Aug 2026

Portalocker provides cross-platform file locking with support for exclusive and shared locks, plus Redis-based distributed locks and process-aware PID file locking.

Install it if you need file or process coordination; the optional extras (pywin32, redis) are only required for specific lock types.

BSD-3-Clausepure Python · 3.10+
65.1Mdownloads / mo
ray Worth it
PyPI · Distributed Computing · released Aug 2026

Ray is a distributed computing framework that scales Python applications from a single machine to multi-node clusters, providing abstractions for parallel tasks, stateful actors, and shared objects.

permissive licensecompiled wheel · 3.10+
63.3Mdownloads / mo

See also c7n-azure · c7n-mailer · c7n-org · custodian · pulumi-policy · cloudsec-audit · cloudsplaining · policy-sentry · oslo.policy · cloudauthz

Further reading