Tirith

Plug IaC governance into any IaC pipeline. Evaluate plans with Tirith, protect sensitive values, enforce centralised policies, and surface actionable results before infrastructure changes are applied.

Blockchain & Cloud ComputingPythonApache-2.0

Abstract

Tirith is an open-source Blockchain & Cloud Computing project. Plug IaC governance into any IaC pipeline. Evaluate plans with Tirith, protect sensitive values, enforce centralised policies, and surface actionable results before infrastructure changes are applied. [](LICENSE) [](CODE_OF_CONDUCT.md) [](https://github.com/psf/black) [](https://sonarcloud.io/summary/new_code?id=StackGuardian_policy-framework) [](https://sonarcloud.io/summary/new_code?id=StackGuardian_policy-framework) [](https://join.slack.com/t/stackguardian-ol78820/shared_invite/zt-2ksag36j9-OjmXqQmyXudgYrV6FmesIQ) [](https://codecov.io/gh/StackGuardian/tirith). It is built using Python, AWS, Terraform. Key capabilities include: An easy to read and simple way to define policy as code against structured formats; Use providers to define policies for terraform plan, infracost or any abstract JSON; Easily evaluate inputs against policy using pre-defined evaluators like ContainedIn, Equals, RegexMatch etc. The complete source code is publicly available on GitHub under the Apache License 2.0, making it a useful reference for students building a Blockchain & Cloud Computing mini project or final-year project.

1. Introduction

[](LICENSE) [](CODE_OF_CONDUCT.md) [](https://github.com/psf/black) [](https://sonarcloud.io/summary/new_code?id=StackGuardian_policy-framework) [](https://sonarcloud.io/summary/new_code?id=StackGuardian_policy-framework) [](https://join.slack.com/t/stackguardian-ol78820/shared_invite/zt-2ksag36j9-OjmXqQmyXudgYrV6FmesIQ) [](https://codecov.io/gh/StackGuardian/tirith)

Tirith reads the plan your pipeline already produces — the output of terraform show -json tfplan — checks it against your policies, and exits non-zero so a violating change never reaches apply. The reason it is a plugin rather than an integration is that one policy set then covers every pipeline you run it from: the same policy files gate a GitHub Actions job, a GitLab job and a laptop, and in platform mode Tirith rules and Checkov findings come back in one verdict instead of two tools you have to reconcile by hand.

It is Apache-2.0 and needs no account. Policies are JSON files in your repository, evaluation happens on your own runner, and nothing is sent anywhere. If you would rather keep policy in one place across many repositories, tirith platform check evaluates against the policies a StackGuardian organization enforces instead — same document, same verdict, same exit codes. That mode is optional and is the only part that talks to a network.

2. Objective

Plug IaC governance into any IaC pipeline. Evaluate plans with Tirith, protect sensitive values, enforce centralised policies, and surface actionable results before infrastructure changes are applied.

This project demonstrates how Python, AWS, Terraform can be applied to a real-world Blockchain & Cloud Computing problem.

3. Key Features / Modules

  • An easy to read and simple way to define policy as code against structured formats.
  • Use providers to define policies for terraform plan, infracost or any abstract JSON.
  • Easily evaluate inputs against policy using pre-defined evaluators like ContainedIn, Equals, RegexMatch etc.
  • Write your own provider (plugin) by leveraging a highly extensible and pluggable architecture to support any input formats.

4. Technology Stack

PythonAWSTerraform
  • Terraform Workflow should require an approval to create or destroy resources

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Python 3.8 or later
  • pip / virtualenv for dependencies
  • VS Code, PyCharm or Jupyter Notebook
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/StackGuardian/tirith.git
cd tirith
  1. Clone the Tirith repository to your system
  2. Change directory to the cloned repository
  3. Setup a virtualenv
  4. Activate the virtualenv
  5. Install Tirith in the virtualenv
  6. Verify that Tirith is installed
  7. Abstract away the implementation complexity of policy engine underneath.
  8. Simplify creation of declarative policies that are easy to read and interpret.
git clone https://github.com/StackGuardian/tirith.git
cd tirith
virtualenv .venv
source .venv/bin/activate

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add a CI/CD pipeline with GitHub Actions
  • Deploy to a public test network or cloud free tier
  • Add monitoring and cost alerts

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Why does this problem need a blockchain or cloud-native design?
  2. Explain the smart contract / infrastructure components and how they interact.
  3. How are gas costs or cloud costs kept under control?
  4. How is the system secured (keys, IAM, access control)?
  5. How would the solution scale to many more users?

9. Source Code & License

This project is developed by StackGuardian and published on GitHub under the Apache License 2.0. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Blockchain & Cloud Computing project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Blockchain & Cloud Computing Internship