Regula
A tool that evaluates infrastructure as code for security and compliance.
Overview
Regula is an open-source tool that evaluates infrastructure as code for security and compliance. It supports a variety of IaC formats and comes with a library of pre-built rules. Regula is designed to be used in CI/CD pipelines to catch issues before they are deployed.
✨ Key Features
- Scans Terraform, CloudFormation, and Kubernetes
- Checks against CIS benchmarks and other compliance standards
- Custom rules with Open Policy Agent (OPA)
- Integration with CI/CD pipelines
- Open-source and community-driven
- Part of the Fugue (now Snyk) ecosystem
🎯 Key Differentiators
- Focus on compliance
- Integration with Open Policy Agent (OPA)
- Part of the Fugue (now Snyk) ecosystem
Unique Value: Provides a powerful and flexible open-source solution for ensuring IaC compliance.
🎯 Use Cases (4)
✅ Best For
- Validating Terraform code against CIS AWS Foundations Benchmark
- Ensuring Kubernetes manifests comply with organizational policies
💡 Check With Vendor
Verify these considerations match your specific requirements:
- Runtime security monitoring
- Vulnerability scanning of application code
🏆 Alternatives
Its tight integration with OPA makes it a great choice for organizations that want to use a standardized policy language.
💻 Platforms
✅ Offline Mode Available
🔌 Integrations
💰 Pricing
Free tier: Full open-source version is free.
🔄 Similar Tools in IaC Compliance
Snyk IaC
Find and fix security issues in Terraform, CloudFormation, Kubernetes, and ARM templates....
Checkov
An open-source static analysis tool for infrastructure as code....
Terrascan
An open-source static code analyzer for Infrastructure as Code....
KICS by Checkmarx
An open-source solution for static analysis of IaC....
tfsec
A static analysis security scanner for Terraform code....
Open Policy Agent
An open-source, general-purpose policy engine....