Cloud Custodian

B
B tier on Infrastructure Policy as Code ToolsScore 7.1 · #5 of 24
Android app
Not listed
Free plan
Yes
Runs on
Linux, Mac, self-hosted, Windows
cloudcustodian.io
The Cloud Custodian homepage

Summary

Cloud Custodian manages cloud resources through policies written in YAML. Each policy names a resource type, filters for selecting resources and actions to apply to matches. It supports security enforcement, compliance, tag policies, cleanup of unused resources and cost management for AWS, Azure and Google Cloud Platform resources. Policies can respond to provider events through serverless features or run periodically as cron jobs. Before actions run, users can validate policies and preview matches in dry-run mode. Runs can generate policy metrics, structured resource records and logs for cloud metrics, storage and logging services. Documented event connections include AWS CloudWatch Events and Config Rules, Azure EventGrid, and GCP AuditLog and Pub/Sub. The project documents installation on Linux, macOS and Windows, as well as operation through Docker or Kubernetes. Kubernetes, Tencent Cloud and OpenStack support are in beta; Terraform integration is in alpha. The project is free and open source under the Apache 2.0 license. One AWS constraint is that event-triggered policies run only in the same region and account, unlike periodic policies, which may run across regions and accounts.

Who it is for

Cloud Custodian suits teams managing cloud resources who want policy-based controls for security, compliance, tagging or cost management. It is relevant to users working with AWS, Azure or Google Cloud Platform resources.

What is good

  • Free and open source under Apache 2.0
  • Supports AWS, Azure and Google Cloud Platform
  • Dry-run previews matching resources before actions
  • Policies can run on events or schedules
  • Produces metrics, resource records and logs

What to know first

  • Kubernetes support is in beta
  • Tencent Cloud and OpenStack support are in beta
  • Terraform integration is in alpha
  • AWS event policies are limited to same region and account

Everything Xiaomi review

Cloud Custodian: the full review

Cloud Custodian offers policy-based controls across three major cloud providers, with preview and reporting options. Note the maturity labels for beta and alpha integrations and the AWS event-policy constraint.

Overview

Cloud Custodian is a policy-as-code tool for teams managing resources across major cloud providers. It is best suited to operators comfortable defining and running YAML policies; the trade-off is that it offers a flexible toolkit rather than a turnkey governance service.

Key features

Policies with a preview step

A policy names a resource type, filters the resources to target, and specifies actions for matches. That pattern can cover security enforcement, compliance, tagging, removal of unused resources, and cost management. Validation and dry-run mode show which resources match before actions execute, a useful safeguard for teams automating consequential changes. Policy testing, admission control, runtime enforcement, CI/CD integration, and reporting are also supported.

Event-driven and scheduled runs

Policies can respond to cloud-provider events through serverless integrations or run periodically as a server cron job. Documented integrations include AWS CloudWatch Events and Config Rules, Azure EventGrid, and GCP AuditLog and Pub/Sub. AWS event-triggered policies must run in the same account and region; periodic policies can run from a different account and region. That distinction matters for teams centralizing scheduled governance across accounts.

Records and deployment

Runs can produce policy metrics, structured resource records, and logs for cloud-provider metrics, storage, and logging services. The project documents installation on Linux, macOS, and Windows, as well as Docker and Kubernetes deployment; execution options include local machines, instances, and AWS Lambda. AWS, Azure, and Google Cloud Platform resources are covered by policy support. Kubernetes, Tencent Cloud, and OpenStack integrations are beta, while Terraform integration is alpha, so teams relying on those should account for their lower maturity.

Pricing

Cloud Custodian is free: its plan costs 0.00 USD per free, billed Free for everyone to use, and is open source under the Apache 2.0 license. There is no free trial because the project is already free. This removes a subscription barrier for teams able to operate the policies themselves; the project does not offer paid tiers with different quotas or seats.

Platforms

Cloud Custodian supports Linux, macOS, Windows, and self-hosted use. Docker and Kubernetes are documented deployment routes, and policies can run locally, on an instance, or through AWS Lambda. The platform options suit teams choosing their own execution environment rather than looking for a single hosted console.

Who it's for

It fits cloud and platform teams that want one policy model for governance tasks across AWS, Azure, and GCP, and that can review YAML and manage execution. Dry runs and reporting help teams control risk and inspect outcomes. It is less suitable for readers seeking a managed product with a graphical workflow, or for teams whose required integration is still in beta or alpha.

Pros and cons

  • Pros: Free, Apache 2.0 software with policy support spanning AWS, Azure, and GCP, making it practical for teams standardizing controls across providers.
  • Pros: Validation and dry runs expose matching resources before actions run, reducing the risk of unintended automated changes.
  • Pros: Event-based and scheduled execution, plus metrics, records, and logs, support both responsive controls and ongoing review.
  • Cons: Policies are written in YAML and users manage their own execution, which puts operational responsibility on the adopting team.
  • Cons: AWS event-triggered policies are constrained to the same account and region, limiting centralized event response across boundaries.
  • Cons: Kubernetes, Tencent Cloud, and OpenStack support is beta, and Terraform integration is alpha, making them less mature choices.

Alternatives

For a broad comparison, see Cloud Governance Software and Infrastructure Policy as Code Tools.

  • OmniGCloud is worth considering when a SaaS workspace and connector-based approach are preferable; its free plan includes one connector, one SaaS workspace, basic CSV export, and a basic audit trail.
  • Kyverno is another free, Apache-licensed open-source option for teams evaluating policy tools across Linux, macOS, Windows, and self-hosted environments.
  • AWS Control Tower may suit teams wanting an AWS service with no additional Control Tower charge, while bearing in mind that underlying AWS services are billed by usage.
  • CGPulse offers a free plan with two cloud accounts, ten scans per month, one tracked initiative, five auto-fixes per month, and watermarked PDF reports; its free trial is another option to evaluate.
  • Kubewarden is a free option for readers comparing policy tools across Linux, macOS, Windows, and self-hosted platforms.
  • Powerpipe is a free, open-source tool from Turbot for teams considering another Linux, macOS, Windows, self-hosted, or web option.
  • AWS Config is a paid, usage-based alternative for AWS-focused readers; charges depend on configuration items recorded, active rules, and other usage.
  • CoreStack Cloud Governance is a paid option for teams seeking a product or bundle with unlimited CoreStack Assessments and willing to request custom pricing.

Verdict

Choose Cloud Custodian if your team wants free, flexible policy automation across AWS, Azure, and GCP and can own YAML authoring and operations. Its preview workflow and varied execution options are compelling; look elsewhere if you need a managed interface or depend on integrations that remain beta or alpha.

Cloud Custodian plans and pricing

All plans
Cloud Custodian Free Free for everyone to use Open source · Apache 2.0 license cloudcustodian.io · 29 Sept 2026

Compared on infrastructure policy as code tools

Free plan
Yescloudcustodian.io

Facts

Purpose
Cloud Custodian manages cloud resources by filtering and tagging them, then applying actions through policies written in a YAML domain specific language.cloudcustodian.io · 29 Sept 2026
Security and cost
It supports security policy enforcement, compliance, tag policies, cleanup of unused resources, and cost management.cloudcustodian.io · 29 Sept 2026
Cloud providers
The documentation describes policy support for AWS, Azure, and Google Cloud Platform resources.cloudcustodian.io · 29 Sept 2026
Beta and alpha support
The homepage says Kubernetes, Tencent Cloud, and OpenStack support is in beta, while Terraform integration is currently in alpha.cloudcustodian.io · 29 Sept 2026
Policy controls
Policies specify a resource type, filters to narrow resources, and actions to apply to matching resources.cloudcustodian.io · 29 Sept 2026
Enforcement
Cloud Custodian integrates with provider serverless features to enforce policies in response to events, and can also run as a cron job on a server.cloudcustodian.io · 29 Sept 2026
Policy preview
Users can validate policies and run them in dry-run mode to see matching resources without executing actions.cloudcustodian.io · 29 Sept 2026
Metrics and records
Runs can produce policy metrics, structured resource records, and logs for cloud provider metrics, storage, and logging services.cloudcustodian.io · 29 Sept 2026
Integration examples
Documented event integrations include AWS CloudWatch Events and Config Rules, Azure EventGrid, and GCP AuditLog and Pub/Sub.cloudcustodian.io · 29 Sept 2026
Deployment options
The project documents installation on Linux, macOS, and Windows, and running through Docker or Kubernetes; its homepage also describes local, instance, and AWS Lambda execution.cloudcustodian.io · 29 Sept 2026
Security reporting
The project asks people to report security vulnerabilities to its security team at [email protected] and says it will acknowledge reports by email.github.com · 29 Sept 2026
Community support
The project points users to Slack, a mailing list, GitHub discussions, and community meetings that are open to users and developers of every skill level.cloudcustodian.io · 29 Sept 2026
Notable execution limit
The AWS documentation says event-triggered policies can run only in the same region and account, while periodic policies may run in a different region and account.cloudcustodian.io · 29 Sept 2026
Maker and history
The site identifies the project as a community project and states that it was accepted to CNCF on June 25, 2020; it does not state a headquarters or founding date.cncf.io · 29 Sept 2026

Best Cloud Custodian alternatives

See all 20

Where it ranks on Everything Xiaomi

Is Cloud Custodian yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources