Infrastructure as Code (IaC) Security Tools

A curated directory of 9 tools for scanning Terraform, CloudFormation, and Kubernetes manifests for misconfigurations before they ever reach production.

  1. Fugue's cloud security posture management (CSPM) engine — built around one policy model across the entire cloud development lifecycle — is now part of the Snyk platform.
  2. Rapid7's cloud-native application protection platform (CNAPP) that drives continuous security and compliance, including IaC scanning, across multi-cloud environments.
  3. A free, open-source static analysis tool that scans Terraform, CloudFormation, Kubernetes, Helm, ARM templates, and Serverless configs for misconfigurations before deployment.
  4. A pluggable Terraform linter that catches possible errors — like invalid instance types — across AWS, Azure, and GCP, plus deprecated syntax and naming-convention issues.
  5. Accurics' self-healing infrastructure-as-code security capability now lives inside Tenable One's CNAPP, codifying security checks throughout the development lifecycle.
  6. CloudSploit's configuration-scanning engine is now Aqua Security's real-time Cloud Security Posture Management product, detecting risks across AWS, Azure, GCP, and Oracle Cloud.
  7. Helps developers find and fix misconfigurations in Terraform, CloudFormation, Kubernetes, Helm, and ARM templates directly inside IDE, CLI, SCM, and CI/CD workflows.
  8. Context-aware infrastructure-as-code security reviews with continuous compliance and drift detection — now run as an independent product after Indeni's acquisition by BlueCat.
  9. Now part of Palo Alto Networks' Prisma Cloud, Bridgecrew (powered by Checkov) enforces cloud security earlier in the development lifecycle to minimize risk and maintain compliance.

More Resources

Containerization IT Operations Cloud-native Computing Home