ctfkit by compliance.tf
ctfkit by compliance.tf runs the same Terraform and OpenTofu checks in every pipeline you have and writes one findings format that your existing policy stack reads. When a compliance.tf module would close a gap, the finding names that module.
The problem
A platform team that owns Terraform standards rarely owns one pipeline. Each pipeline grows its own checks, so the same change can pass in GitHub Actions and fail in Spacelift. The gaps that matter most, such as a raw resource where a hardened module exists, often surface only in an audit sample or in production, when fixing them means migrating live resources.
Why teams use it
- The same binary and settings file run the same checks in a pre-commit hook, GitHub Actions, Spacelift or a shell.
- Findings come out as SARIF for code scanning, JSON for OPA or your own scripts, and Spacelift metadata for a plan policy. ctfkit runs alongside Sentinel, and the policy tool you already use decides what blocks a merge.
- A finding that a compliance.tf module would close carries the module source, for example
soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws. - ctfkit itself opens no network connection and reads no cloud credentials: the control catalog is compiled into the binary, and it never runs
terraformortofu. Your pipeline still needs its usual credentials for the steps ctfkit reads from: a compliance.tf registry token forinit, and cloud credentials forplan. Downloading a ctfkit release needs the release token.
Who it helps
| Who | What they get |
|---|---|
| Platform leads who own Terraform and OpenTofu standards | one set of checks that runs unchanged in every pipeline, rolled out repository by repository or stack by stack |
| Security and compliance teams | a findings record in a standard format, with the rule, the resource, the file and line, and the control when there is one, and a clear statement of what each check does and does not prove. You can review it and store it with your other CI evidence; it is unsigned today, and signing is planned |
| Module authors and developers | fast pre_plan feedback in the pull request and the pre-commit hook, before init and with no credentials |
Where it runs
Commands describes the three stages ctfkit checks at.
- Run checks in GitHub Actions: a public action that comments on the pull request, writes the job summary and uploads SARIF.
- Run checks in Spacelift: two stack hooks and one plan policy, warn first, then deny per stack.
- Pre-commit and any shell: the same binary. The Quickstart runs both scans by hand, and the pre-commit hook setup is in the Install section of the ctfkit README.
Status
Every capability carries a label. Available means it ships in the current release and is supported. Preview means it ships and works, but its interface or behavior can still change. Planned means there is no code behind it today.
| Capability | Status |
|---|---|
scan (pre_plan, post_plan) | available |
| SARIF, JSON, text, pretty, JUnit, Spacelift outputs | available |
report | preview |
| GitHub Action | preview |
| Spacelift hooks and plan policy | preview |
| OPA example (readable with access) | available |
| pre-commit hook | available |
| Analyzer SDK | preview |
| Homebrew, Docker image, HCP Terraform run task | planned |
| Signed evidence | planned |
This documentation describes ctfkit v0.2.1. ctfkit makes no signing, attestation or independent verification claim about its output; signing is planned.
What it is not
- It produces findings and an exit code. It does not decide what your pipeline blocks; OPA, Sentinel or a Spacelift policy does.
- It runs next to the scanner you already use and reports what your configuration requires and which compliance.tf module closes each gap.
- It never reads your cloud accounts or live state.
- It never runs
terraformortofu.
Get access
ctfkit is Apache-2.0 software, available to compliance.tf customers on request. A public open source release is planned.
- Request access, or email mail@compliance.tf.
- On approval, the GitHub users you name get read-only access to the private repository
compliancetf/ctfkit. Its releases carry the binaries, the checksums and the.deb,.rpmand.apkpackages. To download a release, sign the GitHub CLI in with one of those users, or setGH_TOKENto a token with read access to the repository; either works. - Follow the Quickstart to install a release and run your first two scans.
Pages in this section
- Quickstart: install a release and run your first two scans.
- Commands: stages,
scan,report, flags, exit codes and settings. - Run checks in GitHub Actions: the action, tokens, permissions and a complete workflow.
- Run checks in Spacelift: runner image, stack hooks and the plan policy.
- Reference analyzers: every rule ID, its stage and its limits.