Continuous Multi-Cloud Governance
Audit AWS, Azure, Google Cloud and Entra ID from the CI platform you already use. No agents. No infrastructure. Uses your platform's native identity.
- Open Source
- MIT License
- Runs in your CI
StackQL Cross-Cloud Audit
ExampleClouds audited: 4 / 4 connected Checks: 347
Visited: 1,284 nodes / 3,918 queries / 2m 56s
Summary
| Severity | Findings |
|---|---|
| CRITICAL | 3 |
| HIGH | 24 |
| MEDIUM | 61 |
| LOW | 123 |
| Total | 211 |
See It Run
One workflow file, every cloud
Drop the audit into an existing pipeline, point it at your accounts and let it run on a schedule. Every run produces the same report - a ranked list of findings with the exact API state that produced them.
Runs anywhere
Bring the audit to your platform, not the other way around.
- GitHub Actions
- GitLab CI
- Buildkite
- Jenkins
- Azure DevOps
- Google Cloud Build
What it checks
Comprehensive coverage across security, FinOps, identity and best practices.
Security
- Publicly exposed resources
- Open SSH / RDP
- Vulnerable configurations
- Network security
- Encryption & KMS
And 40+ more checks
Identity & IAM
- Overly permissive policies
- Unused / stale access
- Root account usage
- MFA enforcement
- Service account hygiene
And 30+ more checks
FinOps
- Idle resources
- Oversized resources
- Orphaned infrastructure
- Unattached storage
- Savings opportunities
And 25+ more checks
Best Practices
- CIS Benchmarks
- Cloud provider best practices
- Compliance alignment
- Configuration drift
- Tagging and ownership
And 20+ more checks
Every run publishes a report
The audit writes a summary straight into your CI run - severity counts, then every check with the reasoning behind it. Same artifact whether it runs on a schedule, on a pull request, or on demand.
agent-remediation-finops-audit summary
StackQL AWS FinOps Audit
Regions audited: 17 / 17 enabled Checks: 6
Budget: nodes=∞, queries=∞, timeout=1800s Visited: 17 nodes / 103 queries / 60.5s
Summary
| Severity | Findings |
|---|---|
| CRITICAL | 0 |
| HIGH | 2 |
| MEDIUM | 0 |
| LOW | 12 |
| Total | 14 |
Checks
-
Passed: AWS EKS clusters (watch)
EKS cluster control planes flagged for cost review (category=watch). Node cost is covered by compute watch.
No findings.
-
Passed: AWS Running EC2 instances (watch)
Plus 4 further checks in the full report.
Native authentication
Uses your platform's native identity model. No long-lived credentials.
- GitHub OIDC
- GitLab OIDC
- AWS OIDC / IAM Roles
- Azure Workload Identity
- Google Cloud Service Accounts
- And more Bring your own provider
Ready to audit your cloud?
Get started in minutes. Open source. Enterprise ready.