📋 IaC Validation
24 tools compared
🔧 Tools in IaC Validation
Infracost
A tool that shows cloud cost estimates for IaC changes, helping engineers understand the cost impact of their work.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that unifies policy enforcement across the stack.
Datree
A CLI tool for preventing misconfigurations in Kubernetes manifests by running automated checks.
env0
An automation platform for IaC that includes policy-as-code and cost management features.
Scalr
A Terraform automation and collaboration platform with built-in policy-as-code and governance features.
Wiz
A comprehensive cloud security platform that includes IaC scanning as part of its broader capabilities.
Orca Security
An agentless cloud security platform that includes shift-left capabilities like IaC security scanning.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
Snyk Infrastructure as Code
A developer-focused tool for finding and fixing security misconfigurations in IaC files.
Trivy
A versatile security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in containers, IaC, and more.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Terrascan
An open-source static code analyzer for IaC that helps detect security and compliance violations.
KICS
An open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in IaC.
Chef InSpec
An open-source testing framework for infrastructure with a human-readable language for specifying compliance and security rules.
TFLint
A linter for Terraform that focuses on best practices, style conventions, and detecting potential errors.
Kyverno
A policy engine designed specifically for Kubernetes, allowing you to manage and validate configurations as policies.
Terratest
A Go library that provides patterns and helper functions for writing automated tests for infrastructure code.
Regula
A tool that evaluates IaC for security misconfigurations and compliance violations, powered by Open Policy Agent.
Conftest
A utility to help you write tests against structured configuration files using the Rego language.
Kubeval
A tool for validating Kubernetes configuration files against the official Kubernetes OpenAPI schemas.
Kube-score
A static analysis tool for Kubernetes that checks manifests for reliability and security best practices.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
cfn-lint
An open-source linter from AWS for validating CloudFormation templates.
Terragrunt
A wrapper for Terraform that helps manage complex infrastructure by keeping code DRY and managing remote state.