NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #3294 most downloaded on PyPI
Cloud Custodian - Policy Rules Engine
Last release 15 days ago
03 Sep 2026
Ships on a steady schedule
a new release about every 2 months
Rarely documented
notes for 2 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
154 releases · first in 2016
Nothing published for this version
Nothing published for this version
fix set-snapshot-copy-tags action, also mark deprecated
Authors: 42 Pull Requests: 136
One column per quarter.
Nothing published for this version
cli schema support showing mode documentation #3744
Nothing published for this version
cli deprecate metrics subcommand #3597
upgrade pyyaml to 4.2b4 to avoid cve flagging (custodian is unaffected as we use safe load in all cases).
respect max-resources when using cached resources #3478
Nothing published for this version
core - boolean group filters propagate validate & dateutil zoneinfo deprecation fixes
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
support max-resources-percent as percent of total resource count to limit blast radius (supplements max resource count). #2830
Alot of work this release has gone into making the core work nicely with multiple cloud providers, as we work on Azure and GCP support. Many thanks to
Alot of work this release has gone into making the core work nicely with multiple cloud providers, as we work on Azure and GCP support. Many thanks to microsoft team for working on the Azure provider.
c7n schema multiple cloud provider support (#2266)Start of azure support
resources:
Basic provider implementation with support for a handful of resources, no actions yet.
Nothing published for this version
Nothing published for this version
python3 support :-) ! (many prs, thanks @chadwhitacre)
Nothing published for this version
Nothing published for this version
Nothing published for this version
core - resource query switch from set retry to individual page retry (#1661) core - interpolate/replace {account_id} in policy mode: role: for multi-a
core - resource query switch from set retry to individual page retry (#1661) core - interpolate/replace {account_id} in policy mode: role: for multi-account usage (#1559) core - value filter supports intersection operation (#1566) python 3 compatibility better aws config query integration
auto-tag-user for all taggable resources (#1309) iam - delete user action - gc all the associated resources first (#1664) sg - modify groups action - bug fix jsonschema use anyOf instead of oneOf (#1654) rds, rds-snapshot - switch to universal tagging (#1563) (#1648) asg - add image filter #1629 (#1646) appelb - fix bug (#1633) in modify-listener action to operate on all matched listeners (#1636) aws shield support (#1625) catch up on latest aws config supported resources (cfn, dyndb, asg, cw alarm) (#1623) rdscluster - fix arn generation (#1606) glacier, sqs, kms, sns - policy remove statement action (#1575, #1573, #1572) security group filter - correctly handle self-referencing security-groups. (#1599) s3 encrypt extant keys - regression fix/test for kms sufficient when doing aes256 (#1584) account increase limit action - support increase as delta number in addition to percent #1526)
tools/c7n_org add readme (#1670) tools/salactus acl visitor, s3 data events, object reporting, inventory feed, inventory filter and action (#1588) tools/c7n_logexporter - flow log to subscription filter, plus stream archiver micro-batch (#1557)
docs - set-instance-profile fix the example policy (#1668) docs - adding examples for asg tag enforcement (#1632)
Nothing published for this version
resources/account increase-limit action - adding region field to the increase request (#1484) resources/alb set-s3-logging action (#1340) resources/as
resources/account increase-limit action - adding region field to the increase request (#1484)
resources/alb set-s3-logging action (#1340)
resources/asg on resume retry start instances(#1525)
resources/awslambda permission removal action (#1543)
resources/nat-gateway and delete action added. (#1550)
resources/iam-user delete action (#1300)
resources/iam-user remove key action - fix unused access keys date bug #842 (#1489)
resources/ecs correct ecs cluster resource metadata, add metrics filter (#1532)
resources/ecr update doc example (#1538)
resources/ecr remove-statement action (#1537)
resources/ec2 server side query filter support for tenancy (#1510)
resources/ec2 stop action and ephemeral filter - add xvda as additional ebs root device name detection (#1527)
resources/ec2 ami and snapshot support querying third party owned (#982)
resources/efs add filter_name and filter_type to EFS for lambda support (#1520)
resources/efs efs tagging support (#1500)
resources/vpc vpc route-table and peering-connection filters and endpoint resource (#925)
resources/vpc security-group aws config ip perms normalization (#1493)
c7n/core support child resources (based on #981) (#1533) c7n/core functional testing support and Makefile target (#1496) c7n/core aws config (rules and query source) - load supplementary data from config (#907) c7n/core support additional option for in memory cache. (#1271)
tools/c7n_logexporter various clean ups (#1535) tools/c7n_logexporter log exporter cli enhancements (#1503) tools/c7n_mailer adding template util formatter support for account, cloudtrail, rds-snapshot, iam, vpc resources (#1523) tools/c7n_mailer - add back c7n_mailer.replay (#1514) tools/c7n_mailer - if you don't setup caching, don't try to use the caching system (#1495) tools/c7n_mailer - add dead letter queue config option (#1479) tools/c7n_salactus - dependencies switch pin to min required (#1492) tools/c7n_sphere11 alpha sg diff and lock filter and api (#1501) tools/c7n_traildb refactor to python package (#1498)
Nothing published for this version
Nothing published for this version
copyright header - update uniformly with script (#1352) (scotwk)
matched option (#1471) (alfredgamulo)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
fix multi-region output, allow specifying timeout for a lambda policy \#1150 (kapilt)
functional test marker #1009 (whit537)Nothing published for this version
Updated docs to not use -c (or --config) flag, which is deprecated #960 (scotwk)
resources:many support config as query source #899 (kapilt)
version subcommand that prints system info #875 (scotwk)c7n-sentry deploy #861 (whit537)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
ec2 state transition age filter
Features
many bug fixes
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Config rule support, custodian policies can now be executed as custom config rules, with integrated provisioning.
Features
Nothing published for this version
resource specified schedules for offhours (#13), many thanks to @fdosani for contributing in #152
Features
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
policies can now be region specific (for global resources support) and support a max-resources attribute as a safety measure.
Features
Many thanks to the contributors to this release (@ewbankkit, @gwh59, @jimmyraywv, @mandeepbal, @timothystone)
Your coding agent can read these notes before it upgrades. Set up the MCP server →