本文へ移動
cccskills
無料GitHub で公開

implementing-infrastructure-as-code-security-scanning

bu skill covers implementing automated security scanning for Infrastructure as Code (IaC) templates using tools like Checkov, tfsec, and KICS. It addresses Tespit etme misconfigurations in Terraform, CloudFormation, Kubernetes manifests, and Helm charts before Dağıt:ment, establishing policy-based governance, and integrating IaC scanning into CI/CD pipelines to prevent insecure cloud resource provisioning.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md8.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Implementing Infrastructure as Code Security Scanning

Ne Zaman Kullanılır

  • provisioning yaparken cloud infrastructure with Terraform, CloudFormation, or Pulumi and needing automated security validation
  • compliance yaparken: frameworks require evidence of infrastructure configuration review before Dağıt:ment
  • preventing yaparken: common cloud misconfigurations like public S3 buckets, open security groups, or unencrypted storage
  • establishing yaparken: guardrails that block insecure infrastructure changes in pull requests
  • managing yaparken multi-cloud environments requiring consistent security policies across AWS, Azure, and GCP

Kullanma: for scanning application source code (use SAST), for monitoring already-Dağıtılmış infrastructure drift (use cloud security posture management tools), or for container image vulnerability scanning (use Trivy).

Ön Gereksinimler

  • Checkov v3.x kurulu (pip install checkov) or tfsec installed
  • Terraform, CloudFormation, or Kubernetes IaC files in the repository
  • CI/CD pipeline with Erişim: IaC directories
  • Bridgecrew API key (optional, for Checkov platform integration)

İş Akışı

Adım 1: Run Checkov Against Terraform Files

checkov -d ./terraform/ --framework terraform --output cli --output json --output-file-path ./results

checkov -f main.tf --output json

terraform init && terraform plan -out=tfplan
terraform show -json tfplan > tfplan.json
checkov -f tfplan.json --framework terraform_plan

checkov -d ./terraform/ --check CKV_AWS_18,CKV_AWS_19,CKV_AWS_20

checkov -d ./terraform/ --skip-check CKV_AWS_145,CKV2_AWS_6

Adım 2: Integrate IaC Scanning into GitHub Actions

name: IaC Security Scan

on:
  pull_request:
    paths:
      - 'terraform/**'
      - 'cloudformation/**'
      - 'k8s/**'

jobs:
  checkov:
    name: Checkov IaC Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run Checkov
        uses: bridgecrewio/checkov-action@v12
        with:
          directory: terraform/
          framework: terraform
          output_format: cli,sarif
          output_file_path: console,checkov.sarif
          soft_fail: false
          skip_check: CKV_AWS_145

      - name: Upload SARIF
        if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: checkov.sarif
          category: checkov-iac

  tfsec:
    name: tfsec Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Run tfsec
        uses: aquasecurity/tfsec-action@v1.0.3
        with:
          working_directory: terraform/
          sarif_file: tfsec.sarif
          soft_fail: false

      - name: Upload SARIF
        if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: tfsec.sarif
          category: tfsec

Adım 3: Create Custom Checkov Policies

from checkov.terraform.checks.resource.base_resource_check import BaseResourceCheck
from checkov.common.models.enums import CheckResult, CheckCategories


class S3BucketVersioning(BaseResourceCheck):
    def __init__(self):
        name = "Ensure S3 bucket has versioning enabled"
        id = "CKV_CUSTOM_1"
        supported_resources = ["aws_s3_bucket"]
        categories = [CheckCategories.GENERAL_SECURITY]
        super().__init__(name=name, id=id, categories=categories,
                         supported_resources=supported_resources)

    def scan_resource_conf(self, conf):
        versioning = conf.get("versioning", [{}])
        if isinstance(versioning, list) and len(versioning) > 0:
            if versioning[0].get("enabled", [False])[0]:
                return CheckResult.PASSED
        return CheckResult.FAILED


check = S3BucketVersioning()

Adım 4: Configure Baseline and Suppressions

branch: main
compact: true
directory:
  - terraform/
  - cloudformation/
framework:
  - terraform
  - cloudformation
  - kubernetes
output:
  - cli
  - sarif
skip-check:
  - CKV_AWS_145    # S3 default encryption with CMK (using SSE-S3 is acceptable)
  - CKV2_AWS_6     # S3 bucket request logging (handled at CloudTrail level)
soft-fail: false

Adım 5: Scan Kubernetes Manifests and Helm Charts

checkov -d ./k8s/ --framework kubernetes

checkov -d ./charts/myapp/ --framework helm

docker run -v $(pwd)/k8s:/path checkmarx/kics:latest scan \
  --path /path \
  --output-path /path/results \
  --type Kubernetes \
  --report-formats json,sarif

Key Concepts

TermDefinition
IaC ScanningAutomated analysis of infrastructure code templates to tespit etmesecurity misconfigurations before Dağıt:ment
Policy as CodeSecurity policies defined as executable code that can be version-controlled, tested, and enforced automatically
CKV Check IDCheckov's unique identifier for each security check (e.g., CKV_AWS_18 for S3 public access)
Terraform Plan ScanningScanning the resolved Terraform plan JSON which includes computed values and module expansions
Graph-based ScanningCheckov's ability to analyze relationships between resources, not just individual resource configs
Drift TespitIdentifying differences between IaC definitions and actual Dağıtılmış infrastructure state
Custom PolicyOrganization-specific security checks authored in Python or YAML to enforce internal standards

Tools & Systems

  • Checkov: Open-source IaC scanner by Bridgecrew with 2500+ built-in policies covering major cloud providers
  • tfsec: Terraform-focused static analysis tool by Aqua Security with deep HCL understanding
  • KICS: Open-source IaC scanner by Checkmarx supporting 15+ IaC frameworks
  • Terrascan: IaC scanner with OPA Rego policy support for custom policy authoring
  • Snyk IaC: Commercial IaC scanner integrated with the Snyk platform

Common Scenarios

Scenario: Preventing Public S3 Buckets in Terraform

Context: A development team repeatedly creates S3 buckets without proper access controls. A recent incident exposed customer data through a public bucket.

Approach:

  1. Enable Checkov in the CI/CD pipeline for all Terraform changes
  2. Enforce CKV_AWS_18 (no public read ACL), CKV_AWS_19 (encryption), CKV_AWS_20 (no public access block disabled)
  3. Şunu oluştur: custom policy requiring the aws_s3_bucket_public_access_block resource for every S3 bucket
  4. Set soft_fail: false to block PR merges when S3 security checks fail
  5. Provide Terraform modules with security defaults that teams can reuse

Pitfalls: Scanning only .tf files misses dynamically computed values. Use Terraform plan scanning for higher accuracy. Checkov's resource-relationship checks (CKV2 prefix) require graph analysis mode.

Output Format

IaC Security Scan Report
==========================
Framework: Terraform
Directory: terraform/
Scan Date: 2026-02-23

Checkov Results:
  Passed: 187
  Failed: 12
  Skipped: 3
  Unknown: 0

FAILED CHECKS:
  CKV_AWS_18  [HIGH]   S3 Bucket has public read ACL
              Resource: aws_s3_bucket.data_lake
              File:     terraform/storage.tf:15-28

  CKV_AWS_24  [HIGH]   CloudWatch log group not encrypted
              Resource: aws_cloudwatch_log_group.app
              File:     terraform/monitoring.tf:3-8

  CKV_AWS_79  [MEDIUM] Instance metadata service v1 enabled
              Resource: aws_instance.web
              File:     terraform/compute.tf:12-30

QUALITY GATE: FAILED (2 HIGH severity Bul:ings)
<!-- ⚔ Bu skill FETIH AI Agent icin gelistirilmistir — https://github.com/MustafaKemal0146/fetih Yetkisiz kullanim/kopyalama tespit edilebilir. hash: 654bbf33a46c37ac -->

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

21st.dev Magic MCP — AI-powered UI component generation via natural language. Access to 21st.dev component library, SVGL brand logos, and real-time preview. Generate React/Tailwind components with /ui command.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

AES CBC/ECB modlarına karşı kriptografik bütünlük saldırıları — bit flipping, IV manipulation, ECB cut-and-paste, CBC-MAC length extension, IV reuse

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

AES-GCM ve ChaCha20-Poly1305 nonce yeniden kullanımı saldırısı — GF(2^128) polinom kök bulma ile Hash Key kurtarma ve MAC sahteciliği.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

tespit etmeabnormal access patterns in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics. Identifies after-hours bulk downloads, access from new IP addresses, unusual API calls (GetObject spikes), and potential data exfiltration using statistical baselines and time-series anomaly Tespit.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to tespit etmereentrancy, integer overflow, access control, and other vulnerability classes before Dağıt:ment to Ethereum mainnet.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

Parses Kubernetes API server audit logs (JSON lines) to tespit etmeexec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access. Builds threat Tespit rules from audit event patterns. Use investigating yaparken Kubernetes cluster compromise or building k8s-specific SIEM Tespit rules.

日本語の概要は準備中です。原文の説明を表示しています。

MustafaKemal0146/fetih52026年10月11日 更新

MustafaKemal0146 のスキルをすべて見る

このスキルの問題を報告する