Share the content

Overview​

Terraform open source version became very popular reaching more than one billion of downloads, thousands of contributors and widely adopted.

In the last years security vision was evolving from product based solutions  to became pervasive and also present on pipelines, code review branches make relevant steps from consolidate asset inspections to closer conception phases.

Now entering in infrastructure as code maturity stages where organizations can now inspect the IAC code based on policy enforcement.

Implementation

To illustrate this concept we will share aspects from Hashicorp Sentinel and BridgeCrew.

Summary

Both implementations of IAC code security posture are good choice. However depending on requirements one trends to be more attractive:

If you have HashiCorp products Sentinel can be an alternative;

If you use Hashicorp Terraform Enterprise Sentinel can be an alternative

If you look for pre build policies, custom policies based on YAML Bridge Crew can be an alternative.

 

Here a sample code to to play to better understand. SampleGit code.

Bellow he have an example in Visual Code Studio providing an very easy form to enforce control in a more proactive in early stages prior creating the resource using checkcov plugin. Link for plugin install.

An image of a person typing cloud infrastructure automation code. The person can be shown using a laptop,  The background is feature tech-inspired graphics. Use a color scheme that aligns with the website or app's branding.
hcl code snapshot

Share the content

By mike

...passionate technology professional with deep experience in with high volume deployments and mission critical workloads build the orientation on - how to achieve the objectives leveraging key technologies be transparent and most of all a ‘forever student,’. Major aspect here is do using simple never forget enjoy and have fun avoid... Cycling is my major sport, with that I've learned several aspects that can apply on daily bases.... Horse riding is also very nice I try do when I can.... The views expressed on this [blog; website] are my own and do not necessarily reflect the views of Oracle or any other Company that I've worked in past. Today I've help the following certifications: OCI Architect Associate OCI Architect Professional OCI Operations Associate OCI Fundamentals The views expressed on www.simplesample.com blog is my own and do not necessarily reflect the views of Oracle.

Leave a Reply

Your email address will not be published. Required fields are marked *