Aegis-DevOps 0.3.0 compiles AI agent guardrails into AWS SCPs
Open-source project Aegis-DevOps 0.3.0 adds a compiler that turns AI agent policies into AWS Service Control Policies. Restrictions on destructive calls like deleting S3 buckets or RDS databases now apply on the AWS side, not just on the client.
- The compiler turns hook rules into SCPs with explicit Deny for s3:DeleteBucket and rds:DeleteDBInstance
- Identity model is deny-by-default: trusted roles are listed in a signed agents.yaml
- Compilation adds blocks on sts:AssumeRole and iam:PassRole into trusted roles
- Every compile writes a coverage report listing uncovered ways to reach the same effect
Read next
Security