Skip to the content.

Aegis-DevOps

Stop AI agents from running kubectl delete, terraform destroy or DROP TABLE because a ticket told them to.

Aegis-DevOps is an open-source policy guardrail for AI coding agents and DevOps automation. It checks every infrastructure command an agent wants to run — kubectl, terraform/tofu, helm, aws, gcloud, az, argocd, gh, SQL — before it runs, and blocks or escalates it when your policy says no. A policy rule only counts if nobody has edited it since it was signed and its author was allowed to write that kind of rule, so a line planted in a Jira ticket or chat message (prompt injection, context poisoning) cannot become policy.

Aegis-DevOps blocking an injected kubectl delete

Where it runs

Try it in 60 seconds

  1. Watch it block a pull request, with nothing to install: the demo’s example PR deletes a production database and Aegis’s failing check blocks it. Fork the demo repository to try your own change.
  2. Check a command yourself:

    pip install aegis-devops && aegis init .aegis
    aegis check command --pretty -- "kubectl delete namespace prod"   # BLOCK
    aegis check command --pretty -- "kubectl get pods -n prod"        # ALLOW
    
  3. Put it in front of your coding agent (Claude Code shown; others in Coding agents):

    claude plugin marketplace add moneytool/aegis-devops
    claude plugin install aegis-devops@aegis-devops
    

Documentation

Project