Skip to main content

IaC Security: Terraform, Checkov, and Policy

Learn to secure Terraform: keep secrets out of code and state, pin providers and modules, scan with Checkov and Trivy, and enforce rules with Conftest.

~3 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding the Three IaC Risks

How one reviewed pull request opens a port to the world Infrastructure as Code did not remove misconfigurations. It moved them into pull requests.

Keeping Secrets Out of Terraform Code

Keeping provider credentials out of the code Provider credentials in a .tf file end up in Git history forever.

Protecting Terraform State

What a state file contains Terraform state is a complete record of your infrastructure, and it holds attribute values in plain text.

Pinning Providers and Modules

Locking providers with the dependency lock file The .terraform.lock.hcl file records the exact provider versions and cryptographic hashes that...

Scanning with Checkov

Running Checkov on code and on plans Checkov is an open source scanner with hundreds of Terraform checks, and it runs before terraform apply.

Scanning with Trivy Config

Using one scanner for code, images, and dependencies Trivy's config scanner checks Terraform, CloudFormation, Kubernetes manifests, and Dockerfiles...

Skills You'll Master

IAC-SECURITYTERRAFORMCHECKOVPOLICY-AS-CODEDEVSECOPS

Curriculum Index10 topics

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Platform Engineer

    ₹15L - ₹28L a year

    Growing
  • Cloud Engineer

    ₹10L - ₹24L a year

    High Demand
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

No. The sensitive flag only hides the value in terminal output. The value is still written to the state file in plain text, so state must be encrypted and tightly access controlled, or you must use ephemeral values and write-only attributes.

Either one catches common misconfigurations, and many teams run both because their rule sets differ. Trivy is convenient if you already use it for images and dependencies. Checkov has a large Terraform rule library and can scan plan files.

A plan shows the resolved values after variables and modules are expanded, so it reveals what will really be created. Policies written against the plan, such as required tags, can only be checked reliably there.

tfsec has been merged into Trivy and no longer receives new development. You may still meet it in older pipelines, but new projects should use Trivy's config scanner.