Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Terraform
  3. terrascan

terrascan

Apache-2.0Gov1.19.9

A static code analyzer that detects security and compliance violations in Infrastructure as Code before provisioning cloud infrastructure.

Visit WebsiteGitHubGitHub
5.2k stars556 forks0 contributors

What is terrascan?

Terrascan is a static code analyzer that scans Infrastructure as Code (IaC) files for security misconfigurations, compliance violations, and vulnerabilities. It helps developers and DevOps teams identify risks before provisioning cloud infrastructure, supporting multiple IaC providers like Terraform, Kubernetes, and CloudFormation.

Target Audience

DevOps engineers, cloud infrastructure teams, and security professionals who manage Infrastructure as Code and need to enforce security and compliance standards in their CI/CD pipelines.

Value Proposition

Terrascan offers extensive policy coverage across major cloud providers and IaC formats, integrates seamlessly into CI/CD workflows, and provides customizable scanning options to fit specific security requirements.

Overview

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

Use Cases

Best For

  • Scanning Terraform configurations for AWS security best practices
  • Enforcing compliance policies in Kubernetes YAML files
  • Integrating security checks into CI/CD pipelines for Infrastructure as Code
  • Detecting misconfigurations in Azure Resource Manager templates
  • Identifying vulnerabilities in Docker images from container registries
  • Monitoring cloud infrastructure for configuration drift post-deployment

Not Ideal For

  • Projects requiring ongoing maintenance and updates for new cloud services or security threats
  • Teams preferring GUI-based tools over command-line interfaces for easier adoption
  • Use cases needing real-time, dynamic analysis beyond static scanning and drift monitoring

Pros & Cons

Pros

Wide Policy Coverage

Includes over 500 policies for AWS, Azure, GCP, Kubernetes, Docker, and GitHub, ensuring comprehensive security checks across major cloud providers and IaC formats.

Multi-IaC Support

Scans Terraform, CloudFormation, ARM, Kubernetes, Helm v3, Kustomize, and Dockerfiles, making it versatile for diverse infrastructure stacks.

CI/CD Pipeline Integration

Can be seamlessly integrated into CI/CD workflows to enforce security automatically, with documentation providing specific guidance for various pipelines.

Container Vulnerability Scanning

Integrates with AWS ECR, Azure, GCP, and Harbor registries to detect Docker image vulnerabilities, adding a layer of container security beyond IaC.

Cons

Archived Project

The repository is no longer maintained, meaning no future updates, bug fixes, or support for new IaC features, cloud services, or security policies.

Complex Registry Setup

Docker vulnerability scanning requires authentication and environment setup for container registries, which can be cumbersome and error-prone to configure.

Static Analysis Limitations

Primarily focuses on static code analysis and drift monitoring, so it may not detect runtime issues or dynamic misconfigurations in live, provisioned infrastructure.

Frequently Asked Questions

Quick Stats

Stars5,213
Forks556
Contributors0
Open Issues0
Last commit8 months ago
CreatedSince 2017

Tags

#devops#policy-as-code#kubernetes#security-scanning#cloudsecurity#security#terraform#infrastructure-as-code#devsecops#security-tools#compliance#aws#static-analysis#cloud-security

Built With

G
Go
R
Rego
D
Docker

Links & Resources

Website

Included in

Terraform6.3k
Auto-fetched 17 hours ago

Related Projects

terraformerterraformer

CLI tool to generate terraform files from existing infrastructure (reverse Terraform). Infrastructure to Code

Stars14,559
Forks1,836
Last commit4 months ago
InfracostInfracost

Cloud cost intelligence for engineers, AI coding agents, and CI/CD 💰📉 Shift FinOps Left!

Stars12,413
Forks679
Last commit21 days ago
TerragruntTerragrunt

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu/Terraform to scale.

Stars9,726
Forks1,215
Last commit1 day ago
atlantisatlantis

Terraform Pull Request Automation

Stars9,200
Forks1,304
Last commit1 day ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub