Skip to content

IaC security

Infrastructure as code (Terraform, CloudFormation, Ansible, Bicep) defines the cloud and systems in versioned files. That lets you scan infrastructure security before deploying it: a public bucket or an open security group is caught in the PR, not after the breach.

- infra is CODE -> reviewed, versioned, and scanned like code (shift-left)
- a misconfig (public S3, 0.0.0.0/0 SG, no encryption) is caught BEFORE applying
- reproducible and auditable: the desired state is in git, not in manual clicks
- risk: one template error is multiplied across N deployments
- public storage (S3/blob), encryption at rest disabled
- security groups/firewalls too open (0.0.0.0/0, admin ports)
- IAM with excessive permissions (* in actions/resources, see cloud)
- logging/monitoring disabled, no MFA, keys without rotation
- untagged resources (governance) and baseline deviations
Checkov policies for Terraform/CFN/K8s/ARM (broad catalog)
tfsec / Trivy Terraform scanning and more (Trivy unifies IaC/image/SCA)
KICS multi-platform (Checkmarx)
OPA/Conftest custom policies (Rego) -> policy as code
Terrascan, cfn-nag, ansible-lint (security)
- express security policies as code (OPA/Rego, Sentinel) -> gate in CI
- "no public buckets", "encryption mandatory", "no SGs open to the Internet"
- the PR fails if the template violates the policy -> prevention at the source
- drift: the real infra deviates from the code (manual changes) -> re-scan live infra
- handle the Terraform STATE carefully: it contains secrets -> encrypted/remote backend
- detect and reconcile drift; no "ClickOps" outside the code
  • Scan IaC in the PR/CI (Checkov/tfsec/Trivy) and fail on insecure configs.
  • Policy as Code (OPA/Conftest) for the org’s invariants (no public, encryption, etc.).
  • Protect the Terraform state (it contains secrets) and watch for drift.
  • Complement with cloud posture (CSPM, see cloud) for already-deployed infra.
  • Countless breaches from public S3 buckets and open security groups deployed by unscanned IaC.
  • Capital One (2019): a cloud misconfiguration (WAF/IAM); the kind of flaw IaC scanning prevents.
  • Most cloud incidents are misconfigurations, not exploits → IaC scanning is high ROI.
  • IaC scanning in the PR/CI (Checkov/tfsec/Trivy)
  • Policy as Code for invariants (OPA/Conftest)
  • Detect public storage / open SGs / excessive IAM
  • Encryption at rest and logging mandatory by policy
  • Terraform state in an encrypted/remote backend
  • Drift detection and reconciliation
  • Complement with CSPM for deployed infra (cloud)