Skip to content

0xBahalaNa/aws-compliance-as-code

View on GitHub ↗Related repositories →

Automated AWS compliance guardrails using Service Control Policies and CloudFormation. Controls enforce audit log protection, encryption at rest, boundary protection, and least functionality, mapped to CJIS Security Policy v6.0, FedRAMP High baseline, and NIST 800-53 Rev. 5.

active 2026-03-082026-07-22 (UTC)

Partial coverage11,164 / 11,801 hourly files (95%) · 2 absent upstream · 634 failed, retryable2025-04-062026-08-10 (UTC)— sampled evenly across the window, so rankings and trends hold; absolute counts scale up.
Events
66
Pushes
14
Pull requests
11
Issues
26
Stars
0
Forks
0

Activity over time

Daily event counts in the loaded window

Line chart, 137 days from 2026-03-08 to 2026-07-22. Pushes: 14 total, peak 3 in a day. Pull requests: 11 total, peak 4 in a day. Issues: 26 total, peak 10 in a day. Comments: 3 total, peak 2 in a day. Stars: 0 total, peak 0 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
0xBahalaNa5114110
linear[bot]3003

Recent activity

Latest issues, pull requests and releases

  • Issue#320xBahalaNa2026-06-16 01:52
    docs: SCP scp-require-s3-encryption interaction with Layer 4 Config delivery in UseExisting mode
  • Pull request#370xBahalaNa2026-06-10 00:48
  • Pull request#370xBahalaNa2026-06-10 00:48
  • Issue#310xBahalaNa2026-05-27 21:20
    feat: extend compliance/layer/project tag triple from Layer 1 to Layers 2-5
  • Issue#200xBahalaNa2026-05-27 21:14
    feat: lockdown carve-out ergonomics (case-tolerant + multi-role)
  • Issue#330xBahalaNa2026-05-27 20:11
    feat: Config bucket policy admin role parallel to BucketPolicyAdminRole
  • Pull request#280xBahalaNa2026-05-27 16:51
  • Issue comment#27linear[bot]2026-05-27 12:54
    docs: Layer 2 deploy-principal + bucket-policy lockdown recovery scenario
  • Pull request#270xBahalaNa2026-05-27 12:54
  • Issue#250xBahalaNa2026-05-27 04:52
    feat: export BucketPolicyAdminBoundaryArn for cross-stack consumers
  • Issue#230xBahalaNa2026-05-27 04:51
    feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
  • Issue#230xBahalaNa2026-05-27 04:51
    feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
  • Issue#230xBahalaNa2026-05-27 04:51
    feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
  • Issue#230xBahalaNa2026-05-27 04:51
    feat: anchor boundary Deny ARNs to prevent Path/ManagedPolicyName drift
  • Issue comment#22linear[bot]2026-05-27 04:51
    feat: close sibling-role escalation via iam:CreatePolicy + PutRolePermissionsBoundary on un-listed roles
  • Pull request#210xBahalaNa2026-05-27 04:50
  • Pull request#160xBahalaNa2026-05-24 23:42
  • Pull request#160xBahalaNa2026-05-24 23:42
  • Pull request#160xBahalaNa2026-05-24 23:42
  • Pull request#160xBahalaNa2026-05-24 23:42
  • Issue comment#15linear[bot]2026-05-24 20:08
    feat: Layer 5 — GuardDuty + EventBridge + SNS + Security Hub (NIST 800-53)
  • Pull request#140xBahalaNa2026-05-23 21:38
  • Issue#100xBahalaNa2026-05-14 00:41
    Separate retention parameters for CloudTrail vs VPC Flow Logs
  • Issue#40xBahalaNa2026-04-01 00:27
    #4: Deploy KMS CMK with service-level encryption defaults
  • Issue#30xBahalaNa2026-04-01 00:27
    #3: Enforce IAM baseline and organization guardrails

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 0 stars here means stars gained during the window, not the repo's star count.