cfn-guard 3.2.0

AWS CloudFormation Guard is an open-source general-purpose policy-as-code evaluation tool. It provides developers with a simple-to-use, yet powerful and expressive domain-specific language (DSL) to define policies and enables developers to validate JSON- or YAML- formatted structured data with those policies.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
let template = Resources.*[ Type == 'AWS::New::Service']

rule SOME_RULE when %template !empty {
    let policy = %template.Properties.BucketPolicy.PolicyText
    let res = json_parse(%policy)

    %res !empty

    %res.Statement[*]
    {
        Effect == "Deny"
        Resource == "arn:aws:s3:::s3-test-123/*"
    }
}