This release is a pre-release and may not be stable for production use.
BlueArch AWS Steward
Local, MCP-first AWS assessment and remediation planning for Codex, Claude Code, Cursor, and other MCP clients.
Steward reads the current state of your AWS account, finds resources matched by executable rules, explains the evidence and business impact, and builds a reviewable remediation plan. Assessments are read-only by default.
Beta: use Steward as decision support. Review every recommendation and plan before changing production infrastructure.
Install
Steward requires Python 3.10 or newer. Install it in a virtual environment:
python3 -m venv .venv
source .venv/bin/activate
python -m pip install --upgrade bluearch-aws-steward
bluearch-steward --version
bluearch-steward mcp smoke
Windows activation:
.venv\Scripts\activate
For an isolated command without manually managing a virtual environment:
uv tool install --upgrade bluearch-aws-steward
uv tool update-shell
bluearch-steward mcp smoke
EKS and Kubernetes support is included in the standard package. AWS CLI,
kubectl, Terraform/OpenTofu, Helm, Kustomize, Docker, and kind remain
external tools used only by workflows that need them.
Connect Your Agent
bluearch-steward mcp install --client codex
bluearch-steward mcp install --client cursor
bluearch-steward mcp install --client claude
Use --dry-run to preview configuration changes. Restart the client after
registration. For another stdio MCP client:
bluearch-steward mcp config --runtime installed
Run Your First Assessment
Authenticate outside the agent conversation. AWS IAM Identity Center users can run:
aws sso login --profile my-sso-profile
Then ask your MCP client:
Assess my AWS environment. Ask me to select the profile, Region, objectives, and services. Show only resources caught by rules and report skipped rules and coverage. Do not apply changes.
Steward asks for missing context, starts a background assessment, and returns a bounded priority queue. Full results remain queryable and can be exported as JSON, Markdown, HTML, CSV, SARIF, or PDF.
Included In This Preview
- 120 native rules across 17 AWS runtime scopes.
- A 20-rule EKS and Kubernetes assessment and investigation pack.
- Searchable knowledge for the bundled BlueArch AWS misconfiguration catalog.
- Native, Security Hub, Compute Optimizer, Cost Optimization Hub, and optional imported Prowler findings in one deduplicated queue.
- Evidence, risk, confidence, freshness, remediation safety, and cost estimate status on presented findings.
- Read-only resource investigation and planning-only AWS/IaC change previews.
- Guarded writes for a small documented set of low-risk operations only.
Steward is standalone. It does not require BlueArch Core, hosted login, hosted telemetry, or a local AWS inventory database. AWS remains the source of truth.
Safety And Scope
- No assessment applies changes.
- Most recommendations are planning-only.
- Guarded writes require a fresh finding, exact short-lived plan, explicit approval, state revalidation, and post-change verification.
- Missing permissions or unavailable evidence are reported as incomplete, not as passing.
- The current preview is single-account and single-Region per assessment.
Full documentation:
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file bluearch_aws_steward-0.8.0b1.tar.gz.
File metadata
- Download URL: bluearch_aws_steward-0.8.0b1.tar.gz
- Upload date:
- Size: 404.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
44dee022af31161b94f454f6aa96cd326a735f5042a92a9c7bf4fa29dcc2ba55
|
|
| MD5 |
8572297db66ebef8afb124164e1450df
|
|
| BLAKE2b-256 |
30127241d009b5b207dbf28aee34a122d9bdccf94d14b8221e17cb93a63403c2
|
Provenance
The following attestation bundles were made for bluearch_aws_steward-0.8.0b1.tar.gz:
Publisher:
publish-pypi.yml on bluearchio/bluearch-aws-steward
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
bluearch_aws_steward-0.8.0b1.tar.gz -
Subject digest:
44dee022af31161b94f454f6aa96cd326a735f5042a92a9c7bf4fa29dcc2ba55 - Sigstore transparency entry: 2326196617
- Sigstore integration time:
-
Permalink:
bluearchio/bluearch-aws-steward@a39e9e589bd7f933cee95bfed4efbed3ea51fdef -
Branch / Tag:
refs/tags/v0.8.0b1 - Owner: https://github.com/bluearchio
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a39e9e589bd7f933cee95bfed4efbed3ea51fdef -
Trigger Event:
release
-
Statement type:
File details
Details for the file bluearch_aws_steward-0.8.0b1-py3-none-any.whl.
File metadata
- Download URL: bluearch_aws_steward-0.8.0b1-py3-none-any.whl
- Upload date:
- Size: 434.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
764ab6fccf21f24bbdb8f350cf00695bb54536f5855368572774928b6bc73592
|
|
| MD5 |
15d98c8221610aec1abee251b2f2c14f
|
|
| BLAKE2b-256 |
47bb2c06c16d07ccf7c65eb1084876cf592800073c06498a4c37374a5b725b6d
|
Provenance
The following attestation bundles were made for bluearch_aws_steward-0.8.0b1-py3-none-any.whl:
Publisher:
publish-pypi.yml on bluearchio/bluearch-aws-steward
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
bluearch_aws_steward-0.8.0b1-py3-none-any.whl -
Subject digest:
764ab6fccf21f24bbdb8f350cf00695bb54536f5855368572774928b6bc73592 - Sigstore transparency entry: 2326196644
- Sigstore integration time:
-
Permalink:
bluearchio/bluearch-aws-steward@a39e9e589bd7f933cee95bfed4efbed3ea51fdef -
Branch / Tag:
refs/tags/v0.8.0b1 - Owner: https://github.com/bluearchio
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish-pypi.yml@a39e9e589bd7f933cee95bfed4efbed3ea51fdef -
Trigger Event:
release
-
Statement type: