AppSecNews

IaC Security

Infrastructure as Code Security

Catch misconfigurations in Terraform, Kubernetes manifests and cloud templates before deploy.

17 tools profiled

How it differs Scans Terraform, Kubernetes manifests and other infrastructure definitions before they are applied. Scanning the built images is container security.

License
Subcategory
Deployment
Languages
Integrations
Maturity
Signals
Clear

3 tools match

  • Conftest

    Open Policy Agent

    IaC Security

    A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.

    Open source
    Established Verified
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    IaC Security

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source
    Established Verified
  • Terrascan

    Tenable

    IaC Security

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source
    Established
  • Conftest

    Open Policy Agent

    A CLI that parses configuration files into structured data and tests them against policies you write in Rego, the Open Policy Agent language.

    Open source Established
    IaC Security
  • OPA Gatekeeper

    Open Policy Agent (CNCF)

    The Kubernetes admission controller for Open Policy Agent, packaging Rego policies as reusable constraint templates and cluster-scoped constraints.

    Open source Established
    IaC Security
  • Terrascan

    Tenable

    A Go-based static analyzer for infrastructure as code that normalizes multiple formats and evaluates them against Rego policies.

    Open source Established
    IaC Security
Tick up to 4 tools above.