DEV Community

Diana Loomis for StackGuardian

Posted on

Meet Tirith, StackGuardian's Open-Source Policy Engine

Hacktoberfest: Maintainer Spotlight

Tirith (GitHub: https://github.com/StackGuardian/tirith) is StackGuardian's open-source policy as code framework. It reads the JSON your pipeline already produces, such as the output of terraform show -json, and checks it against policies stored as JSON files. Each rule passes, fails, or is skipped, and the result names the resource and value behind it. Tirith is licensed under Apache 2.0, needs no account, and runs on your own machine or CI runner.

Why Tirith?

There is no new policy language to learn. You pick a provider, an operation, and a condition such as Equals, ContainedIn, or RegexMatch, then combine checks with &&, ||, and !.

Built-in providers cover:

  1. Terraform plans
  2. Infracost cost estimates
  3. Kubernetes manifests
  4. StackGuardian workflow configurations
  5. Any JSON document

That means one framework can block a public S3 bucket, cap EC2 spend at 100 USD a month, and require liveness probes on every pod.
Because policies live in your repository, the same files gate a GitHub Actions job, a GitLab pipeline, and a local run. With --fail-on-error, Tirith exits with code 3 on a violation, so a non-compliant change never reaches apply. Two recent additions help while you write policies:

  • tirith lint catches broken policies in pre-commit hooks.
  • tirith ui, currently in beta, is a terminal interface for exploring results and building policies.

Who is it for?

Tirith is for DevSecOps, platform, and cloud teams that need infrastructure guardrails without building their own policy engine. Tirith is also the engine behind StackGuardian's policy checks, and StackGuardian users can run tirith platform check to test a plan against their organization's central policies.

Get Started

Tirith is not on PyPI, so install it from GitHub:
pip install git+https://github.com/StackGuardian/tirith.git
Then evaluate a plan:
tirith -policy-path policy.json -input-path plan.json

Want to contribute?

The project welcomes new providers, evaluators, bug fixes, and pull request reviews. Read the contributing guide (https://github.com/StackGuardian/tirith/blob/main/CONTRIBUTING.md), open an issue to get one assigned. And if you have questions, drop them in the StackGuardian Slack community (https://join.slack.com/t/stackguardian-ol78820/shared_invite/zt-2ksag36j9-OjmXqQmyXudgYrV6FmesIQ).

Top comments (0)