AppSecNews

IaC Security

Infrastructure as Code Security

Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.

17 tools profiled

How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

2 tools match

  • Kyverno

    The Kyverno Project (CNCF)

    IaC Security

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source
    Established Verified
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    IaC Security

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source
    Established Verified
  • Kyverno

    The Kyverno Project (CNCF)

    A Kubernetes-native policy engine that enforces, mutates and generates resources through admission webhooks, with policies written as YAML.

    Open source Established
    IaC Security
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source Established
    IaC Security
Tick up to 4 tools above.