Audit-first security automation

Cross-platform hardening baselines without surprise production changes.

PagerWesi helps security, platform, and compliance teams run audits, review plan manifests, apply limited remediations, collect rollback evidence, and export machine-readable reports across Linux, Windows, macOS, FreeBSD, Alpine, AWS, Azure, GCP, Kubernetes, Docker, Terraform plans, source trees, and network endpoints.

Audit by default Plan manifests AWS rollback SARIF/JSON Secure logging Container image
$ pagerwesi aws --mode plan \
  --plan-manifest reports/aws-plan.json

[!] AWS-S3-004 FAIL arn:aws:s3:::example
    Evidence: NoSuchPublicAccessBlockConfiguration
    Planned change: {} -> {"BlockPublicAcls": true, ...}

Summary: pass=18, fail=2, error=0, skip=0, manual=0
13 Targets: OS, cloud, container, code, and network
4 Modes: audit, plan, apply, rollback
6 Outputs: text, JSON, SARIF, HTML, manifests, container
214 Tests with 67% code coverage

Capabilities

Built for safe audits, reviewable evidence, and controlled change.

Cloud posture baseline

AWS, Azure, GCP, and Kubernetes checks cover high-value storage exposure, logging, monitoring, network exposure, identity, key management, RBAC, and pod security. Azure, GCP, and Kubernetes support plan mode for non-mutating change preview.

Controlled remediation

AWS apply mode supports selected S3 settings, EBS encryption by default, IAM Access Analyzer, and VPC Flow Logs when an approved destination is configured. Policy validation uses JSON Schema for precise error reporting.

Rollback evidence

AWS rollback restores supported manifest-backed changes including S3 public access, default encryption, EBS encryption-by-default, tool-created Access Analyzers, and VPC Flow Logs. Irreversible operations are reported as manual.

OS and local scanners

Linux, macOS, Windows, FreeBSD, and Alpine scripts cover host baselines. Docker, secrets, Terraform plan, and network/TLS scanners add explicit scoped evidence for local and CI/CD workflows.

Enriched SARIF reporting

SARIF output includes full descriptions, help URIs, NIST CSF / ISO 27001 / CIS framework tags, security-severity scores, and markdown remediation guidance. JSON findings are documented with a reusable schema for downstream ingestion.

Container image

A pre-built container image is published to GitHub Container Registry (GHCR) on every release. Run audits in CI/CD pipelines without installing Python dependencies.

Secure by design

Structured logging with automatic secret redaction, SSRF-protected webhook notifications, input validation on all CLI data, rate-limited API calls with exponential backoff retry, and concurrent provider execution with error isolation.

Workflow

Audit first, review the plan, apply only when the evidence is clear.

  1. 01

    Audit

    Inventory posture and export findings as text, JSON, or SARIF.

  2. 02

    Plan

    Generate before/after manifests for AWS, Azure, and GCP without mutation APIs.

  3. 03

    Apply

    Confirm limited, deterministic AWS remediations with explicit acknowledgement.

  4. 04

    Rollback

    Restore supported AWS settings from the recorded change manifest.

Controls

Practical controls for common infrastructure risk areas.

AWS

S3 public access, encryption, versioning, CloudTrail, Config, GuardDuty, Security Hub, EBS/RDS encryption, VPC Flow Logs, Access Analyzer, KMS rotation, and Organizations posture. Full plan, apply, and rollback support.

Azure

Storage TLS, Key Vault public access, SQL auditing, NSG administrative exposure, Defender plans, activity logs, and diagnostic settings. Plan mode available.

GCP

Cloud Storage public IAM, service-account keys, KMS rotation, firewall exposure, logging sinks, audit logging, and Security Command Center. Plan mode available.

Kubernetes

NetworkPolicy coverage, cluster-admin RBAC bindings, privileged pod detection, and Pod Security Standards enforcement. Plan mode available.

Local Scanners

Docker daemon and container checks, source-tree secret detection, Terraform plan review, and network/TLS endpoint validation with explicit path or endpoint scope.

OS

Linux firewall/SSH/patching, macOS firewall/Gatekeeper/FileVault guidance, Windows firewall/SMB/auditing, plus FreeBSD and Alpine/container host baselines.

Container

Run audits anywhere without local Python setup.

$ docker pull ghcr.io/wahidhendrawan/pagerwesi:latest

$ docker run --rm \
  -e AWS_ACCESS_KEY_ID -e AWS_SECRET_ACCESS_KEY \
  ghcr.io/wahidhendrawan/pagerwesi:latest \
  aws --format sarif --output /dev/stdout

Start

Install only the provider extras you need, then run the first audit.

python3 -m venv .venv
. .venv/bin/activate
pip install -e '.[aws]'
pagerwesi policy validate --policy policy.example.yml
pagerwesi aws --format json --output reports/aws.json

Use it for

  • Internal security assessments
  • Pre-production guardrail reviews
  • Evidence-driven remediation workflows
  • SARIF ingestion into GitHub code scanning
  • CI/CD pipeline security gates
Open quickstart View control catalog Permission examples