SteveL
09/08/2025, 7:44 AMMuhammad Shujat Hussain
09/08/2025, 6:02 PMTed Harwood
09/10/2025, 5:29 PMUmair Khan
09/15/2025, 1:31 PMMichael Davis
09/15/2025, 6:33 PMMichael Davis
09/17/2025, 12:24 PMMichael Davis
09/17/2025, 1:27 PMMichael Davis
09/17/2025, 1:27 PMPhe Nguyen
09/17/2025, 9:33 PMAnish
09/19/2025, 12:43 PMSteveL
09/19/2025, 2:37 PMkapilt
09/22/2025, 6:15 PMAnish
09/25/2025, 9:15 PMThomas Heute
09/30/2025, 7:45 AMcustodian and c7n-org to update tags on ~150 AWS accounts.
Running from my machine (Mac), I noticed that running the command over and over (to go through the 150 accounts), my machine starts to crawl. At some point I can't make any network connection unless I stop the loop and wait a few minutes.
It seems that network connections might be left open, has anyone experienced this issue with custodian ?Michael Davis
10/03/2025, 6:46 PMOmendra Gakkhar
10/08/2025, 7:10 PMPong
10/14/2025, 7:07 PMGianncarlo G
10/16/2025, 3:31 PM- type: invoke-lambda . Does this purely just invoke the lambda? I'm wondering if I have the code, that it will upload my lambda if it's missing.Pong
10/17/2025, 7:36 PMmach
10/22/2025, 1:27 PMPong
10/24/2025, 5:54 PMPong
11/04/2025, 5:26 PMPong
11/05/2025, 4:54 PMAZURE_FUNCTION_SUBSCRIPTION_ID / AZURE_FUNCTION_MANAGEMENT_GROUP_NAME variables. The only docs I can find around this is here. Are these just used to override the default subscription that is selected when I run az login beforehand on a per subscription level, and to deploy a single function app (which will reside in the subscriptioin I am currently in ) which will operate against all subscriptions that the management group has control over?John Jack
11/10/2025, 3:19 PMJohn Jack
11/10/2025, 3:19 PMkapilt
11/11/2025, 7:14 PMPong
11/12/2025, 7:06 PMcorey
11/24/2025, 1:51 PMc7n-org in combination with custodian validate? I power my setup with c7n-org and have historically been running custodian validate as part of pull request validation. I added some vars to the c7n-org config file for the first time, and it’s broken the custodian validate logic since the variables aren’t resolved by custodian.
c7n-org config:
accounts:
- account_id: '0000000000'
name: xxxxx
regions:
- us-east-1
- us-west-2
role: arn:aws:iam::0000000000:role/xxxxx
vars:
lambda_runtime: python3.12
# etc etc
Policy:
policies:
- name: xxxxx
# ...
mode:
type: cloudtrail
# ...
runtime: "{lambda_runtime}"
Error:
2025-11-24 13:25:41,565: custodian.commands:ERROR Error on policy:xxxxx resource:xxxxx
'{lambda_runtime}' is not one of ['python3.10', 'python3.11', 'python3.12', 'python3.13']
Failed validating 'enum' in schema[1]['properties']['runtime']:
{'enum': ['python3.10', 'python3.11', 'python3.12', 'python3.13']}Jose
11/25/2025, 1:10 PMJose
11/26/2025, 11:35 AM