awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
cloudquery avatar

cloudquery/cloudquery

0
View on GitHub↗
6,438 stars·547 forks·Go·MPL-2.0·18 viewscloudquery.io↗

Cloudquery

CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses.

The system distinguishes itself by transforming complex, nested cloud API responses into flat relational tables, enabling the use of standard SQL for asset querying and analysis. It employs a modular plugin system for data extraction and driver-based adapters for destination-agnostic loading, allowing metadata to be pushed into diverse storage backends.

The platform covers several broad capability areas, including cloud security posture management, FinOps cost optimization, and infrastructure compliance auditing. It utilizes SQL-based transformation pipelines to implement security frameworks, detect configuration drift, and identify underutilized resources. Additionally, the tool provides event-driven responses to fire webhooks or alerts when policy violations occur.

Features

  • Cloud Provider Metadata Extraction - Pulls infrastructure and service data from cloud providers, SaaS applications, and databases for centralized analysis.
  • Cloud Asset Inventory Managers - Queries cloud provider APIs to retrieve and display consolidated lists of infrastructure assets in a centralized registry.
  • Cloud Metadata Transformations - Applies pre-built transformation projects to raw cloud metadata to implement security frameworks or asset inventories.
  • Relational Data Transformations - Maps nested cloud API responses into flat relational tables for consistent SQL-based querying.
  • API-to-Relational Mappers - Transforms complex, nested cloud API responses into flat relational tables to enable analysis using standard SQL.
  • Cloud Metadata Ingestors - Ingests technical and operational metadata from cloud services into databases and data lakes for long-term storage.
  • SQL Data Loading and Transformation - Processes raw ingested metadata into structured security and compliance reports using SQL as the primary transformation logic.
  • SQL Infrastructure Querying - Analyzes infrastructure state using SQL to identify resource configurations, missing tags, and cost patterns.
  • Metadata Synchronizers - Automates the synchronization of resource configurations from multiple cloud providers into a centralized destination.
  • Cloud Infrastructure Data Collection - Provides programmatic collection of resource metadata from cloud provider APIs for centralized infrastructure analysis.
  • Metadata ETL Pipelines - Provides a data pipeline that extracts resource metadata from cloud providers and SaaS sources into relational databases.
  • Azure Resource Extraction - Retrieves configuration and state data from Microsoft Azure services and loads it into a destination for analysis.
  • GCP Resource Extraction - Retrieves configuration data from Google Cloud Platform APIs and loads it into a specified data destination.
  • Multi-Cloud Data Aggregation - Retrieves resource information from multiple cloud providers and aggregates it into a structured data store for analysis.
  • Cloud Security Posture Management - Identifies misconfigured cloud resources and security vulnerabilities to manage and improve the overall security posture.
  • Data Destination Connectors - Implements driver-based adapters to establish connections and push metadata into various target storage systems and databases.
  • Data Warehouse Exporters - Transfers collected cloud metadata into databases, data lakes, or data warehouses for long-term storage and querying.
  • Operational Signal Exports - Sends synchronized cloud data to external analysis tools and alerting systems to create actionable operational signals.
  • Cloud Infrastructure Cost Optimization - Identifies underutilized or orphaned cloud resources to reduce unnecessary operational spending.
  • Security Posture Dashboards - Provides customizable dashboards for monitoring security posture and infrastructure health based on synchronized data.
  • Event-Driven Workflow Triggers - Initiates automated workflows, webhooks, or alerts based on detected configuration drift or policy violations in synchronized data.
  • Cloud Cost Analytics - Extracts resource cost and usage data to identify savings opportunities and underutilized assets.
  • Compliance Frameworks - Transforms raw cloud metadata into structured security reports based on industry-standard compliance frameworks.
  • Audit and Compliance - Verifies organizational adherence to security policies and regulatory standards using SQL-based guardrails.
  • Resource Compliance Monitoring - Continuously tracks cloud resource configurations against policy definitions to detect untagged assets and unauthorized regional deployments.
  • Infrastructure Policy Enforcement - Defines SQL-based guardrails to evaluate live infrastructure against security or compliance rules.
  • Configuration-Driven Pipelines - Employs pre-defined configuration schemas to automate the setup of data flows between specific sources and destinations.
  • Plugin-Based Architectures - Utilizes a modular plugin system to fetch raw metadata from diverse cloud APIs and SaaS platforms via standardized interfaces.
  • Data Integration - High-performance ELT framework with pluggable architecture.
  • Query Engines - Extracts and loads cloud assets into normalized PostgreSQL tables.
  • AWS Security - Framework for real-time cloud data analysis and alerting.
  • Cloud Security - Transforms cloud infrastructure into queryable SQL tables.
  • Continuous Security Monitoring - Exposes cloud configuration as SQL for security analysis.
  • Cybersecurity - Audits and evaluates configurations of cloud assets.

Star history

Star history chart for cloudquery/cloudqueryStar history chart for cloudquery/cloudquery

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does cloudquery/cloudquery do?

CloudQuery is a cloud infrastructure ETL tool and multi-cloud data pipeline designed to collect, synchronize, and normalize resource metadata from various cloud providers and SaaS platforms. It functions as a centralized asset inventory manager and security posture manager, extracting configuration and state data into relational databases, data lakes, or data warehouses.

What are the main features of cloudquery/cloudquery?

The main features of cloudquery/cloudquery are: Cloud Provider Metadata Extraction, Cloud Asset Inventory Managers, Cloud Metadata Transformations, Relational Data Transformations, API-to-Relational Mappers, Cloud Metadata Ingestors, SQL Data Loading and Transformation, SQL Infrastructure Querying.

What are some open-source alternatives to cloudquery/cloudquery?

Open-source alternatives to cloudquery/cloudquery include: mlabouardy/komiser — Komiser is a multi-cloud infrastructure inspector and asset inventory manager. It provides a centralized system for… alfresco/prowler — Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for… toniblyx/prowler — Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance… cdk-team/cdk — CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure… dlt-hub/dlt — dlt is a Python data ingestion tool and ETL pipeline framework designed to fetch data from diverse sources and persist… capitalone/cloud-custodian — Cloud Custodian is a multi-cloud governance engine and policy enforcement tool designed to automate security,…

Open-source alternatives to Cloudquery

Similar open-source projects, ranked by how many features they share with Cloudquery.
  • mlabouardy/komisermlabouardy avatar

    mlabouardy/komiser

    4,133View on GitHub↗

    Komiser is a multi-cloud infrastructure inspector and asset inventory manager. It provides a centralized system for auditing, cataloging, and analyzing deployed services and assets across AWS, GCP, and Azure environments. The project transforms disparate resource schemas from different cloud vendors into a unified structural representation through a provider-based plugin architecture. It uses agentless API inspection and polling-based resource discovery to retrieve metadata and configuration states without requiring agents on target resources. The platform covers financial management via cos

    Go
    View on GitHub↗4,133
  • alfresco/prowlerAlfresco avatar

    Alfresco/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security posture management platform and vulnerability scanner. It provides tools for automating security audits, evaluating cloud infrastructure against regulatory compliance frameworks, and managing security assessments through a dedicated analysis dashboard. The project distinguishes itself by providing an AI-driven security context server that feeds structured data to AI assistants for automated risk analysis. It also employs graph-based attack path mapping to visualize potential lateral movement and exploitation routes across cloud inventories. The platform cove

    Python
    View on GitHub↗14,005
  • toniblyx/prowlertoniblyx avatar

    toniblyx/prowler

    14,005View on GitHub↗

    Prowler is a multi-cloud security scanner and security posture management tool. It automates security and compliance assessments across multiple cloud environments to identify misconfigurations and vulnerabilities. The project provides a multi-cloud security analysis engine that operates as an automated auditor, evaluating infrastructure against industry-standard regulatory frameworks and security benchmarks. It features a cloud security visualization dashboard that uses a graph database to map cloud inventory and visualize potential attack paths. Capabilities include automated cloud infrast

    Python
    View on GitHub↗14,005
  • cdk-team/cdkcdk-team avatar

    cdk-team/CDK

    4,692View on GitHub↗

    CDK is a specialized toolset for container security auditing, container escape exploitation, and cloud infrastructure pentesting. It provides a collection of scripts and tools designed to identify and exploit vulnerabilities in container runtimes to break out of isolated environments and execute commands on the underlying host operating system. The project features a dedicated Docker runtime exploit suite for abusing the Docker API, procfs, and cgroups to gain unauthorized host-level access. It includes specific techniques for bypassing isolation via LXCFS, user namespace exploitation, and ho

    Go
    View on GitHub↗4,692
  • See all 30 alternatives to Cloudquery→