aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Cloud-Native
  • Software Engineering

Cloud Custodian Goes Beyond The Cloud To Bring Governance As Code To Kubernetes And IaC

  • aster.cloud
  • October 31, 2022
  • 3 minute read

This week the Cloud Custodian project, part of the CNCF incubator, added a Kubernetes admission controller for easy event-driven policy management within your cluster.  The project also added support for running policies against HashiCorp’s Terraform. With these additions, Cloud Custodian represents a single tool that enables comprehensive, frictionless governance for cloud-native infrastructure, including infrastructure as code (IaC), cluster, and cloud environments. The project reduces the operational complexity of learning and implementing multiple tools and workflows.

Cloud Custodian: The De Facto Standard for Public Cloud Governance

Cloud Custodian is a leading governance as a code tool. With the tool, organizations can use code to manage and automate the enforcement of policies for cloud cost optimization, security, compliance, and operations—without hindering developer velocity. Over the past few years, Cloud Custodian has become the de facto standard for public cloud governance. Thousands of organizations now rely upon the tool, including Capital One, Code 42, Grupo, HBO Max, Intuit Inc, JP Morgan Chase & Co, Siemens, Premise Data, and Zapier.


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

Cloud Custodian is a lightweight tool that leverages a simple, domain-specific language for policy authoring. Consequently, policies can easily be created, used, and modified by a range of teams, including development, operations, and security. Notifications and remediation actions can be incorporated into policies. Cloud Custodian integrates tightly with serverless runtimes to provide real-time remediation and response while minimizing operational overhead.

Cloud Custodian’s Simple Declarative Language and Experience Extend to Kubernetes Clusters

Cloud Custodian now brings the same experience, vocabulary, and ergonomics to enforcing policies in Kubernetes environments. Using the same language and tool, teams can establish automated detection and remediation in their Kubernetes clusters.

Read More  The Evolution Of The Nydus Image Acceleration

“Kubernetes adoption has rapidly grown within organizations and is moving beyond pilot projects,” said Sonny Shi, a Cloud Custodian maintainer and Staff Engineer at Stacklet. “We have had various requests from users within the community for Kubernetes support. Teams want to use Cloud Custodian for similar things in Kubernetes, such as enforcing labeling rules and regulatory compliance standards on their clusters. To meet these needs, we have added support for Kubernetes. These capabilities feature a familiar policy language and documentation, so it’s ready to use from day one.”

“Cloud Custodian has helped us enforce security guardrails while enabling our developers to innovate more quickly in the public cloud,” said Mrunal Shah, cloud native security leader at HBO Max. “I am excited to try Cloud Custodian for Kubernetes. Cloud Custodian’s YAML-based language is straightforward. These capabilities can simplify policy enforcement in Kubernetes, and reduce the number of tools we use to secure our cloud native Infrastructure.”

Cloud Custodian Enables Proactive Policy Enforcement Against Terraform Code

More and more organizations are using Infrastructure as code (IaC tools, such as Hashicorp Terraform, to automate the deployment and provisioning of their cloud infrastructure. Given IaC source code and templates essentially define your cloud infrastructure, it is critical to ensure they comply with your organizational policies.

Cloud Custodian users can now validate that their IaC code complies with policies. This effectively enables teams to shift policy validation left. Teams can verify that IaC code adheres to corporate cloud policy before that code is employed to provision cloud infrastructure. Developers can also use this capability to “test” their IaC implementation. In the latest release, Cloud Custodian adds support for HashiCorp’s Terraform language, and there are plans to add support for other languages in the future.

Read More  Data Jugglers. Coding Our Way Through the Database Circus.

“Cloud Custodian enables you to check cloud deployments against policy and remedy policy violations,” said Kapil Thangavelu, Cloud Custodian creator and maintainer and CTO at Stacklet. “With the tool’s new shift-left capabilities, teams can run policy validation earlier and fix issues at the source. All these additional capabilities enable you to use the same language, tools, and workflows to enforce governance of your entire cloud native infrastructure.”

 

 

By Cloud Custodian maintainers
Source CNCF


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • Cloud Custodian
  • CNCF
  • Hashicorp
  • Kubernetes
  • Terraform
You May Also Like
View Post
  • Software Engineering

Embedded Swift Improvements Coming in Swift 6.3

  • November 22, 2025
Visual Studio Code
View Post
  • Software Engineering

Visual Studio 2026 is here: faster, smarter, and a hit with early adopters

  • November 12, 2025
View Post
  • Software Engineering

Introducing Google Gen AI .NET SDK

  • October 24, 2025
View Post
  • Software Engineering

Julia 1.12 Highlights

  • October 13, 2025
View Post
  • Engineering
  • Software Engineering

Development gets better with Age

  • October 9, 2025
View Post
  • Software Engineering

The Growth of the Swift Server Ecosystem

  • September 27, 2025
men with computer website information and chat bubbles vector illustration
View Post
  • Software
  • Software Engineering

What is an ISV (independent software vendor)?

  • August 27, 2025
aster-cloud-erp-bill_of_materials_2
View Post
  • Software
  • Software Engineering

What is an SBOM (software bill of materials)?

  • July 2, 2025

Stay Connected!
LATEST
  • digital-nomad-freelancer-worker-2151205464 1
    One paperwork problem – Get your Digital Nomad Visa employment documents fast from UK, EU or Singapore
    • June 16, 2026
  • 2
    Samsung Art Store Brings Art Basel to Homes Worldwide With New Curated Collection
    • June 15, 2026
  • 3
    You Do Not Need to Invest in the IPO of SpaceX, Anthropic, and OpenAI
    • June 10, 2026
  • 4
    The consequences of relying on AI for accurate news
    • June 10, 2026
  • 5
    Connecting AI agents with unstructured data using Google Cloud Storage MCP Servers
    • June 10, 2026
  • 6
    WWDC26: Apple unveils next generation of Apple Intelligence, Siri AI, powerful parental controls, and an expansive set of software improvements
    • June 8, 2026
  • 7
    IBM and Google Cloud Announce Strategic Partnership to Scale AI with Human Expertise and AI‑Powered Delivery
    • June 4, 2026
  • Data center 8
    Data Sovereignty in Spain. It’s Not Just About the Law, It’s About Efficiency
    • June 3, 2026
  • 9
    Ink vs Pixels. What you miss versus what you are actually missing.
    • June 1, 2026
  • 10
    Banks race to patch new cyber vulnerabilities, and other cybersecurity news
    • May 25, 2026
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • pope-leo-xiv-cq5dam-1500.844 1
    Pope Leo XIV to Publish First Encyclical on Artificial Intelligence and Human Dignity on 25 May
    • May 22, 2026
  • 2
    Portfolio to Clients, and is Strengthened by Ongoing Project Glasswing Work
    • May 20, 2026
  • reMarkable Paper Pure 3
    Everything The reMarkable Paper Pure Actually Does
    • May 14, 2026
  • 4
    Scaling cloud and AI: Microsoft Azure’s commitment to Europe’s digital future
    • May 11, 2026
  • Anthropic Institute 5
    Introducing The Anthropic Institute
    • March 11, 2026
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.