Checkov
Checkov, from Prisma Cloud, reads your IaC files before they are deployed and reports insecure settings, for example a public S3 bucket or an unencrypted volume, with the id of the policy that failed.
Key concepts #
- Policy: a rule such as
CKV_AWS_18. - Skip: suppress a rule with an inline comment and a reason.
- Runs in CI, next to TFLint and Trivy.
Learn it #
See Terraform security scanning with TFLint, Checkov and Trivy.