Aegis-DevOps
Stop AI agents from running kubectl delete, terraform destroy or DROP TABLE because a
ticket told them to.
Aegis-DevOps is an open-source policy guardrail for AI coding agents and DevOps automation. It
checks every infrastructure command an agent wants to run — kubectl, terraform/tofu,
helm, aws, gcloud, az, argocd, gh, SQL — before it runs, and blocks or escalates
it when your policy says no. A policy rule only counts if nobody has edited it since it was
signed and its author was allowed to write that kind of rule, so a line planted in a Jira
ticket or chat message (prompt injection, context poisoning) cannot become policy.

Where it runs
- Coding agents: a pre-tool hook for Claude Code (plugin), OpenAI Codex, GitHub Copilot (CLI and VS Code), Cursor, Gemini CLI (extension) and OpenCode — see Coding agents.
- CI: the Aegis-DevOps Plan Check GitHub Action checks a Terraform or OpenTofu plan on every pull request. See it block a pull request that deletes a production database in the demo repository — fork it and try your own change in two minutes, no cloud account needed.
- Server-side (preview): the same policy compiled to AWS Service Control Policies and Kubernetes ValidatingAdmissionPolicies scoped to agent identities, so the cloud or cluster refuses the call whatever the client — see Server-side enforcement.
Try it in 60 seconds
- Watch it block a pull request, with nothing to install: the demo’s example PR deletes a production database and Aegis’s failing check blocks it. Fork the demo repository to try your own change.
-
Check a command yourself:
pip install aegis-devops && aegis init .aegis aegis check command --pretty -- "kubectl delete namespace prod" # BLOCK aegis check command --pretty -- "kubectl get pods -n prod" # ALLOW -
Put it in front of your coding agent (Claude Code shown; others in Coding agents):
claude plugin marketplace add moneytool/aegis-devops claude plugin install aegis-devops@aegis-devops
Documentation
- Coding agents — install and what gets blocked, per agent
- CLI reference —
aegis check, exit codes, snapshots, compile, identity audit - Writing constraints — rules, scopes, authority, environments
- Configuration — config directory, signing, Git sources,
agents.yaml - Server-side enforcement — AWS SCPs and Kubernetes admission policies
- Benchmark — Aegis against OPA and LLM self-checks on poisoned rules
Project
- Source: github.com/moneytool/aegis-devops
- Package: pypi.org/project/aegis-devops
- Cite: doi.org/10.5281/zenodo.22950337
- License: Apache-2.0