Regula checks infrastructure as code templates (Terraform, CloudFormation, k8s manifests) for AWS, Azure, Google Cloud, and Kubernetes security and compliance using Open Policy Agent/Rego
The main features of fugue/regula are: Infrastructure as Code Analysis, Workflow Automation, Workflow Utilities, Infrastructure Security.
Open-source alternatives to fugue/regula include: bridgecrewio/checkov — Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as… checkmarx/kics — Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle… bridgecrewio/yor — Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified… anmolnagpal/terraform-ai-skills — 🤖 AI-powered Terraform module management across AWS, GCP, Azure, DigitalOcean - Save 97% of maintenance time. 0xdones/tfgen — Terraform code generator for consistent codebase and DRY. alexnabokikh/tfsort — A CLI utility to sort Terraform variables and outputs.
Checkov is a static analysis tool and security scanner designed to identify misconfigurations in infrastructure as code, container images, and Kubernetes configurations. It functions as a cloud security posture tool, an SCA vulnerability scanner, and a secret scanning utility to prevent security breaches and version control leaks. The project distinguishes itself through deep graph analysis and variable resolution, allowing it to map relationships between interconnected resources and evaluate the final state of infrastructure attributes. It provides extensibility for defining custom security
Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.
Extensible auto-tagger for your IaC files. The ultimate way to link entities in the cloud back to the codified resource which created it.