What it does
Conftest is a policy test runner rather than a scanner with opinions. It takes configuration files, parses them into JSON-shaped data using format-specific parsers, and hands that data to Rego rules you supply. A rule that produces a deny or warn message causes the file to fail. There are no built-in security checks: what Conftest ships is the plumbing, and the policy content is yours.
Its parser set is the practical reach of the tool. It understands YAML and JSON natively, plus HCL and Terraform plan output, Dockerfiles, INI, TOML, edn, Jsonnet, XML, CUE and several others. Policies are distributed as OCI artifacts or plain directories, so a platform team can publish a policy bundle to a registry and have every repository pull the same version. Because the engine is OPA, the same Rego you write for Conftest can often be reused in Gatekeeper or an OPA sidecar, which is the main architectural reason teams pick it.
Where it fits
Conftest runs in CI and on developer machines, typically as a step that fails a pull request before a manifest or Terraform plan is applied. It is operated by whoever owns the policy, usually a platform or security engineering group, with developers consuming the failures. The prerequisite is real: someone on your team has to be comfortable in Rego and willing to maintain a policy library. Without that, Conftest gives you nothing.
Strengths
- One policy language across file formats, so Kubernetes manifests, Terraform plans and Dockerfiles are tested the same way.
- Policy bundles distributed through OCI registries make versioning and rollout look like any other artifact pipeline.
conftest verifylets you unit test your policies, which matters once a policy library grows past a handful of rules.- Rego skills transfer directly to admission control and runtime authorization use cases.
Limitations
- No built-in rule content. You start from zero, which is a significant investment compared to a scanner that ships hundreds of checks.
- Rego has a genuine learning curve. Its evaluation model surprises people used to imperative languages, and debugging a rule that silently matches nothing is common.
- It sees only what the parser exposes. Terraform source scanned without a plan leaves unresolved variables, and complex templating upstream is invisible.
Who it suits
Right for platform teams that already run OPA, have opinionated internal standards that no off-the-shelf ruleset encodes, and want those standards enforced identically in CI and at admission. Wrong for a small team looking for fast coverage of common cloud misconfigurations, who will get further sooner with a scanner that ships its own checks.
Used Conftest? Recommend it under your own name and title.
Recommend this tool