Continuous Multi-Cloud Governance

Audit AWS, Azure, Google Cloud and Entra ID from the CI platform you already use. No agents. No infrastructure. Uses your platform's native identity.

  • Open Source
  • MIT License
  • Runs in your CI

StackQL Cross-Cloud Audit

Example

Clouds audited: 4 / 4 connected Checks: 347

Visited: 1,284 nodes / 3,918 queries / 2m 56s

Summary


Severity Findings
CRITICAL 3
HIGH 24
MEDIUM 61
LOW 123
Total 211

See It Run

One workflow file, every cloud

Drop the audit into an existing pipeline, point it at your accounts and let it run on a schedule. Every run produces the same report - a ranked list of findings with the exact API state that produced them.

The audit running in CI, from OIDC authentication through to the published job summary.

Runs anywhere

Bring the audit to your platform, not the other way around.

  • GitHub Actions
  • GitLab CI
  • Buildkite
  • Jenkins
  • Azure DevOps
  • Google Cloud Build

What it checks

Comprehensive coverage across security, FinOps, identity and best practices.

Security

  • Publicly exposed resources
  • Open SSH / RDP
  • Vulnerable configurations
  • Network security
  • Encryption & KMS

And 40+ more checks

Identity & IAM

  • Overly permissive policies
  • Unused / stale access
  • Root account usage
  • MFA enforcement
  • Service account hygiene

And 30+ more checks

FinOps

  • Idle resources
  • Oversized resources
  • Orphaned infrastructure
  • Unattached storage
  • Savings opportunities

And 25+ more checks

Best Practices

  • CIS Benchmarks
  • Cloud provider best practices
  • Compliance alignment
  • Configuration drift
  • Tagging and ownership

And 20+ more checks

Every run publishes a report

The audit writes a summary straight into your CI run - severity counts, then every check with the reasoning behind it. Same artifact whether it runs on a schedule, on a pull request, or on demand.

agent-remediation-finops-audit summary

StackQL AWS FinOps Audit


Regions audited: 17 / 17 enabled Checks: 6

Budget: nodes=∞, queries=∞, timeout=1800s Visited: 17 nodes / 103 queries / 60.5s

Summary


Severity Findings
CRITICAL 0
HIGH 2
MEDIUM 0
LOW 12
Total 14

Checks


  • Passed: AWS EKS clusters (watch)

    EKS cluster control planes flagged for cost review (category=watch). Node cost is covered by compute watch.

    No findings.

  • Passed: AWS Running EC2 instances (watch)

Plus 4 further checks in the full report.

An actual run summary, reproduced here in the site theme.

Native authentication

Uses your platform's native identity model. No long-lived credentials.

  • GitHub OIDC
  • GitLab OIDC
  • AWS OIDC / IAM Roles
  • Azure Workload Identity
  • Google Cloud Service Accounts
  • And more Bring your own provider

Ready to audit your cloud?

Get started in minutes. Open source. Enterprise ready.