Posts under IaC

daredevil

Security Superfriends Episode 7: James Sörling

Security architect and open source contributor James Sörling talks about open source tools that make high velocity development more secure.

A New Security Mandate for Scanning Infrastructure as Code

Scanning IaC should be a security mandate to reduce security risk for your organization. Learn how to get it done in a way that scales with modern software development.

The iacbot Security Practitioner Demo

Learn about iacbot – a free service making it easy for developers to secure their infrastructure as code - Terraform, Cloudformation, Kubernetes. Watch the demo, and give it a try.

Introducing iacbot

Introducing iacbot

Learn about iacbot - a free GitHub app that analyzes Terraform, CloudFormation and Kubernetes changes for security vulnerabilities and provides fast feedback directly in pull requests.

a rolling rock gathers no moss

Rob Schoening

Minimizing Tech Debt With IaC

Tech debt can accumulate quickly as teams use IaC to provision cloud infrastructure. Learn how to minimize tech debt and remediation work by catching and fixing security issues early in development.

Infrastructure as Code

Rob Schoening

A Guide to Open Source IaC Testing

Are You Using Infrastructure as Code (IaC), such as Terraform, CloudFormation, Helm, or Kubernetes? Read about available IaC security testing tools - like Terrascan, Checkov, TFLint, Tf-sec, Sentinel, and others – and how they compare. 

blowing something up

Rich Seiersen

Risk Ranking Terraform Changes

Need a way to assess the security impact of Terraform changes? Soluble helps customers understand the impact of code changes on their security posture.

A leaky bucket

Rich Seiersen

Getting More Out of Cloud Security Posture Management (CSPM)

Mistakes happen! No matter how many controls and processes you put in place — services can and do get exploited by the bad guys because of errors from many developers deploying rapidly to the cloud.