steampipe
by turbot
Steampipe enables real-time SQL querying of APIs and cloud services without the need for ETL or a database.
Zero-ETL, infinite possibilities. Live query APIs, code & more with SQL. No DB required.
Primary Use Case
Steampipe is designed for security, compliance, and cloud engineers who need to perform compliance auditing, risk assessment, and security automation by querying live data from multiple APIs using familiar SQL syntax. It simplifies access to diverse data sources by translating APIs into queryable tables, enabling faster and concurrent data retrieval without managing databases.
- Zero-ETL approach to query APIs and services
- Real-time live data querying with SQL
- High-speed and concurrent queries across multiple data sources
- Single binary CLI tool for local use and CI/CD integration
- Extensive plugin ecosystem mapping APIs to database tables
- Supports over 145 APIs with more than 2000 documented tables
- Multiple distributions including CLI, Postgres FDWs, and SQLite extensions
- Comprehensive documentation and community support
Installation
- For MacOS: brew install turbot/tap/steampipe
- For Linux or Windows (WSL2): sudo /bin/sh -c "$(curl -fsSL https://steampipe.io/install/steampipe.sh)"
- Install a plugin, e.g., steampipe plugin install hackernews
Usage
>_ steampipe plugin install hackernewsInstalls the Hacker News plugin to enable querying Hacker News API data.
>_ steampipe queryStarts an interactive SQL query session against installed plugins and their API-mapped tables.
>_ select * from hackernews_new limit 10Example SQL query to retrieve the latest 10 entries from the Hacker News new stories table.
- Leverages SQL familiarity to accelerate querying of live cloud and API data, improving real-time compliance auditing and risk assessment.
- Ideal for blue teams to automate continuous security posture monitoring across multi-cloud environments without managing complex ETL pipelines or databases.
- Can be integrated into CI/CD pipelines to enable security gate checks and automated compliance validation before deployment.
- Supports rapid development of custom queries and dashboards, empowering purple teams to simulate attack surface discovery and validate detection rules.
- Extensive plugin ecosystem allows expansion to new APIs and services, enabling comprehensive visibility across hybrid environments.
Docs Take 2 Hours. AI Takes 10 Seconds.
Ask anything about steampipe. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.
3 free chats per tool • Instant responses • No credit card
Related Tools

unleash
Unleash/unleash
Open-source feature management platform
the-practical-linux-hardening-guide
trimstray/the-practical-linux-hardening-guide
This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
how-to-secure-anything
veeral-patel/how-to-secure-anything
How to systematically secure anything: a repository about security engineering
404StarLink
knownsec/404StarLink
404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目
Security-101
microsoft/Security-101
8 Lessons, Kick-start Your Cybersecurity Learning.

glpi
glpi-project/glpi
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing.
