compliance.tf

ctfkit by compliance.tf

ctfkit by compliance.tf runs the same Terraform and OpenTofu checks in every pipeline you have and writes one findings format that your existing policy stack reads. When a compliance.tf module would close a gap, the finding names that module.

Terraform checks without and with ctfkit by compliance.tf Two panels. Without ctfkit, GitHub Actions and Spacelift each run their own ad-hoc checks, results differ per pipeline, and module gaps are found late at audit or in production. With ctfkit by compliance.tf, every pipeline runs the same checks and writes one findings format (SARIF, report, Spacelift metadata) that OPA, code scanning and other policy tools already read, runs alongside Sentinel, and names the compliance.tf module that closes each gap. WITHOUT CTFKIT WITH CTFKIT BY COMPLIANCE.TF SURFACES LATER GitHub Actionsown ad-hoc checks Spaceliftown ad-hoc checks Results differ per pipelinedifferent rules, no shared format Module gaps found lateat audit or in production Your pipelinesGitHub Actions · Spacelift · pre-commit ctfkit by compliance.tfthe same checks in every pipeline One findings formatSARIF · report · Spacelift metadata Your policy stackOPA, code scanning Fix for each gapcompliance.tf module LEGENDYour pipelinesctfkitCheck or resultOutcome or existing tool

The problem

A platform team that owns Terraform standards rarely owns one pipeline. Each pipeline grows its own checks, so the same change can pass in GitHub Actions and fail in Spacelift. The gaps that matter most, such as a raw resource where a hardened module exists, often surface only in an audit sample or in production, when fixing them means migrating live resources.

Why teams use it

  • The same binary and settings file run the same checks in a pre-commit hook, GitHub Actions, Spacelift or a shell.
  • Findings come out as SARIF for code scanning, JSON for OPA or your own scripts, and Spacelift metadata for a plan policy. ctfkit runs alongside Sentinel, and the policy tool you already use decides what blocks a merge.
  • A finding that a compliance.tf module would close carries the module source, for example soc2.compliance.tf/terraform-aws-modules/s3-bucket/aws.
  • ctfkit itself opens no network connection and reads no cloud credentials: the control catalog is compiled into the binary, and it never runs terraform or tofu. Your pipeline still needs its usual credentials for the steps ctfkit reads from: a compliance.tf registry token for init, and cloud credentials for plan. Downloading a ctfkit release needs the release token.

Who it helps

WhoWhat they get
Platform leads who own Terraform and OpenTofu standardsone set of checks that runs unchanged in every pipeline, rolled out repository by repository or stack by stack
Security and compliance teamsa findings record in a standard format, with the rule, the resource, the file and line, and the control when there is one, and a clear statement of what each check does and does not prove. You can review it and store it with your other CI evidence; it is unsigned today, and signing is planned
Module authors and developersfast pre_plan feedback in the pull request and the pre-commit hook, before init and with no credentials

Where it runs

Commands describes the three stages ctfkit checks at.

Status

Every capability carries a label. Available means it ships in the current release and is supported. Preview means it ships and works, but its interface or behavior can still change. Planned means there is no code behind it today.

CapabilityStatus
scan (pre_plan, post_plan)available
SARIF, JSON, text, pretty, JUnit, Spacelift outputsavailable
reportpreview
GitHub Actionpreview
Spacelift hooks and plan policypreview
OPA example (readable with access)available
pre-commit hookavailable
Analyzer SDKpreview
Homebrew, Docker image, HCP Terraform run taskplanned
Signed evidenceplanned

This documentation describes ctfkit v0.2.1. ctfkit makes no signing, attestation or independent verification claim about its output; signing is planned.

What it is not

  • It produces findings and an exit code. It does not decide what your pipeline blocks; OPA, Sentinel or a Spacelift policy does.
  • It runs next to the scanner you already use and reports what your configuration requires and which compliance.tf module closes each gap.
  • It never reads your cloud accounts or live state.
  • It never runs terraform or tofu.

Get access

ctfkit is Apache-2.0 software, available to compliance.tf customers on request. A public open source release is planned.

  1. Request access, or email mail@compliance.tf.
  2. On approval, the GitHub users you name get read-only access to the private repository compliancetf/ctfkit. Its releases carry the binaries, the checksums and the .deb, .rpm and .apk packages. To download a release, sign the GitHub CLI in with one of those users, or set GH_TOKEN to a token with read access to the repository; either works.
  3. Follow the Quickstart to install a release and run your first two scans.

Pages in this section

On this page

Ask AI about this

Help improve this page