compliance.tf

What is IaC compliance scanning?

IaC compliance scanning is automated inspection of infrastructure-as-code sources or plans, such as Terraform HCL or plan JSON, that flags settings violating security or compliance rules before the infrastructure is deployed.

How it works

Each run starts from one of two inputs:

InputWhen it runsStrengthWeakness
Source files (HCL)Before terraform initQuick, needs no credentials, works in a pre-commit hookCannot see values known only after planning
Plan JSON (terraform show -json)After terraform planSees the values known at plan timeA plan must exist first, which usually needs cloud credentials; values known only after apply stay unknown

A run reports findings in a format such as SARIF, JSON or JUnit. By itself that output stops nothing; the build fails only when a CI step, a policy engine, or a code-scanning gate says so. Checkov and Trivy are common open-source options. Both parse Terraform plus CloudFormation, Kubernetes manifests, and Dockerfiles, and their bundled rules cover frequently used resource types, not all types.

Scanning counts as a detective control: it exposes an issue inside a change, yet it does not prevent that issue from being written.

How compliance.tf applies it

compliance.tf modules block misconfiguration in the resources they create; a scanner reviews everything else, so run both.

ctfkit is the CI checker from compliance.tf. It executes the same Terraform and OpenTofu checks in a pre-commit hook, GitHub Actions, Spacelift, or a plain shell. If a finding matches a gap that a compliance.tf module would close, the finding names that module's source. It makes no network connection, reads no cloud credentials, and never invokes terraform or tofu on its own.

ctfkit scan --stage pre_plan ./infra                        # source, before init
ctfkit scan plan.json --format sarif --out findings.sarif   # plan JSON, for code scanning

ctfkit is available on request; see the reference analyzers page for current coverage.

Sources

On this page

Ask AI about this

Help improve this page