IaC Security: Terraform, Checkov, and Policy
Learn to secure Terraform: keep secrets out of code and state, pin providers and modules, scan with Checkov and Trivy, and enforce rules with Conftest.
What You'll Learn
Understanding the Three IaC Risks
How one reviewed pull request opens a port to the world Infrastructure as Code did not remove misconfigurations. It moved them into pull requests.
Keeping Secrets Out of Terraform Code
Keeping provider credentials out of the code Provider credentials in a .tf file end up in Git history forever.
Protecting Terraform State
What a state file contains Terraform state is a complete record of your infrastructure, and it holds attribute values in plain text.
Pinning Providers and Modules
Locking providers with the dependency lock file The .terraform.lock.hcl file records the exact provider versions and cryptographic hashes that...
Scanning with Checkov
Running Checkov on code and on plans Checkov is an open source scanner with hundreds of Terraform checks, and it runs before terraform apply.
Scanning with Trivy Config
Using one scanner for code, images, and dependencies Trivy's config scanner checks Terraform, CloudFormation, Kubernetes manifests, and Dockerfiles...
Skills You'll Master
Curriculum Index10 topics
Understanding the Three IaC Risks
How one reviewed pull request opens a port to the world Infrastructure as Code did not remove misconfigurations.
Keeping Secrets Out of Terraform Code
Keeping provider credentials out of the code Provider credentials in a .tf file end up in Git history forever.
Protecting Terraform State
What a state file contains Terraform state is a complete record of your infrastructure, and it holds attribute values...
Pinning Providers and Modules
Locking providers with the dependency lock file The .terraform.lock.hcl file records the exact provider versions and...
Scanning with Checkov
Running Checkov on code and on plans Checkov is an open source scanner with hundreds of Terraform checks, and it runs...
Scanning with Trivy Config
Using one scanner for code, images, and dependencies Trivy's config scanner checks Terraform, CloudFormation...
Writing Organisation Rules with Conftest
Why you need rules your scanner does not know Checkov and Trivy catch widely known bad patterns.
Running IaC Security in CI and Catching Drift
Pull request checks with OIDC and a read-only role The pull request workflow scans the code with no cloud access, then...
Running the Hands-On Lab: Scan and Fix Insecure Terraform
Before you start This lab is fully offline.
Quick Reference and Common Mistakes
Quick reference Common mistakes Believing that sensitive = true protects a secret is the most common state mistake.
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- Growing
Platform Engineer
₹15L - ₹28L a year
- High Demand
Cloud Engineer
₹10L - ₹24L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
No. The sensitive flag only hides the value in terminal output. The value is still written to the state file in plain text, so state must be encrypted and tightly access controlled, or you must use ephemeral values and write-only attributes.
Either one catches common misconfigurations, and many teams run both because their rule sets differ. Trivy is convenient if you already use it for images and dependencies. Checkov has a large Terraform rule library and can scan plan files.
A plan shows the resolved values after variables and modules are expanded, so it reveals what will really be created. Policies written against the plan, such as required tags, can only be checked reliably there.
tfsec has been merged into Trivy and no longer receives new development. You may still meet it in older pipelines, but new projects should use Trivy's config scanner.