StackGuardian launches Tirith, open-source policy-as-code for Terraform and OpenTofu
StackGuardian released Tirith, an Apache 2.0 policy-as-code framework that evaluates Terraform and OpenTofu plan JSON against JSON-defined policies. It runs locally or in CI with no account and returns exit codes 0, 1 or 3 for pipeline gating.
- Tirith is Apache 2.0, runs locally or in CI with no account, requires Python 3.8+
- Policies are JSON files using Equals, ContainedIn, RegexMatch and &&, ||, ! logic
- Exit codes: 0 for pass, 3 for policy failure, 1 for evaluation errors
- Built-in providers: Terraform/OpenTofu plans, Infracost, Kubernetes manifests, JSON
Read next
Software