c7n-org
Cloud Custodian - Parallel Execution
Decision gist · record as of 2026-08-14
Yes. c7n-org is actively maintained, has low install friction, carries no known vulnerabilities, and solves a real operational need for anyone managing multiple cloud accounts. The permissive Apache-2.0 license removes legal friction. Install it if you use Cloud Custodian and manage more than one account or subscription.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9.2 or later (up to 3.x); cloud credentials (AWS IAM role, Azure credentials, GCP service account, or OCI config) must be configured before execution.
- Low install friction; depends only on c7n and click.
- Active maintenance with a release 78 days ago and continuous repository activity.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license; you can use, modify, and distribute this package freely in commercial and private projects without restriction.
last release 2026-05-28 (78 days) · last repo commit 2026-08-14 · 6,043 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 6,922,072 downloads/mo, #1,810 on PyPI
Alternatives
Verify before relying
pip install c7n-org
# Create accounts.yml with your account configuration
# Then run policies across accounts:
c7n-org run -c accounts.yml -s output -u policy.yml- Whether parallel execution across regions is truly automatic by default or requires explicit configuration.
- Performance characteristics and typical execution time for large account sets.
- Whether the package handles credential rotation or session refresh during long-running multi-account operations.
What it is and what it does
c7n-org is a command-line tool that extends Cloud Custodian to orchestrate policy execution across multiple cloud accounts or subscriptions in parallel. Instead of running policies account-by-account, you define all your accounts in a YAML configuration file and c7n-org distributes policy execution across them, collecting results into a structured output directory. It supports AWS (via Organizations API), Azure, GCP, and OCI, and provides filtering by account name, ID, tags, regions, and policies.
The tool operates in several modes: `run` executes Custodian policies across accounts, `run-script` executes arbitrary scripts with cloud credentials injected, `report` generates CSV summaries from policy results, `validate` checks policies without cloud access, and `aws-accounts` auto-generates AWS account configuration from your Organizations API. Variables defined per-account are interpolated into policies at execution time, allowing account-specific customization without duplicating policy files.
Use it for
- Enforce tagging standards across all AWS accounts in an organization in a single command.
- Run compliance policies (e.g., encryption, public access checks) on multiple Azure subscriptions in parallel.
- Generate a cross-account report of non-compliant resources and remediation actions taken.
- Validate policy syntax and variable expansion before deploying to production accounts.
- Execute cleanup scripts (e.g., terminate orphaned resources) across GCP projects with environment variables injected.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
c7n-org is actively maintained, has low install friction, carries no known vulnerabilities, and solves a real operational need for anyone managing multiple cloud accounts. The permissive Apache-2.0 license removes legal friction. Install it if you use Cloud Custodian and manage more than one account or subscription.
Install
c7n-org on PyPI
Before you install
Low install friction; depends only on c7n and click. Active maintenance with a release 78 days ago and continuous repository activity.
Requires Python 3.9.2 or later (up to 3.x); cloud credentials (AWS IAM role, Azure credentials, GCP service account, or OCI config) must be configured before execution.
License in practice
Apache-2.0 permissive license; you can use, modify, and distribute this package freely in commercial and private projects without restriction.
Quickstart
pip install c7n-org
# Create accounts.yml with your account configuration
# Then run policies across accounts:
c7n-org run -c accounts.yml -s output -u policy.yml
Verify before relying
- Whether parallel execution across regions is truly automatic by default or requires explicit configuration.
- Performance characteristics and typical execution time for large account sets.
- Whether the package handles credential rotation or session refresh during long-running multi-account operations.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release <4.0.0,>=3.9.2 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesc7nclick |
| Maintenance | Actively maintained 78 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 6,922,072 / month, #1,810 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | License :: OSI Approved :: Apache Software LicenseTopic :: System :: Distributed ComputingTopic :: System :: Systems Administration |
Evidence: c7n_org-0.6.50-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “multi-account cloud policy execution”
- c7n-orgRuns Cloud Custodian policies in parallel across multiple AWS…
- c7nCloud Custodian is a rules engine that enforces cloud infrastructure…
- c7n-azureAn Azure plugin for Cloud Custodian that automates policy-driven…
Give your agent the search over MCP, or paste the wish link into any chat.
More Distributed Computing packages
gRPC Python is an HTTP/2-based RPC framework that enables you to define and call remote procedures across network boundaries using protocol buffers for serialization.
Install it if you need RPC communication in a distributed system or are integrating with existing gRPC services.
execnet lets you spawn and communicate with Python interpreters across local processes, remote hosts, and different platforms, using a simple API for task distribution and inter-process messaging.
However, the aging maintenance status (275 days since last release) means you should verify it meets your concurrency and performance needs before committing to a…
Cloudpickle extends Python's standard pickle module to serialize lambda functions, interactively-defined functions and classes, and other constructs that the default pickle cannot handle, making it suitable for cluster computing and remote code execution.
Install it if you need to serialize lambda functions, interactively-defined code, or non-standard Python constructs for cluster computing or distributed execution.
Provides a unified, open()-compatible Python API for streaming large files from remote storage (S3, GCS, Azure, HDFS, SFTP, HTTP) and local filesystems, with transparent compression support.
Install it if you work with large files on cloud storage or remote systems and want to avoid writing boilerplate around multiple SDKs.
Portalocker provides cross-platform file locking with support for exclusive and shared locks, plus Redis-based distributed locks and process-aware PID file locking.
Install it if you need file or process coordination; the optional extras (pywin32, redis) are only required for specific lock types.
Ray is a distributed computing framework that scales Python applications from a single machine to multi-node clusters, providing abstractions for parallel tasks, stateful actors, and shared objects.
See also c7n · c7n-azure · c7n-mailer · cloudsplaining · custodian · cloudauthz · pulumi-policy · policy-sentry · django-organizations · policyuniverse