Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. DevSecOps
  3. Terragoat

Terragoat

Apache-2.0HCLv0.6.0

A vulnerable-by-design Terraform repository for learning cloud security misconfigurations across AWS, Azure, and GCP.

Visit WebsiteGitHubGitHub
1.3k stars5.8k forks0 contributors

What is Terragoat?

TerraGoat is a vulnerable-by-design Terraform repository created by Bridgecrew for cloud security training. It provides intentionally insecure infrastructure-as-code configurations across AWS, Azure, and GCP to demonstrate common security misconfigurations that can slip into production environments. The project helps DevSecOps teams learn how to identify and prevent these vulnerabilities through hands-on practice.

Target Audience

Cloud security engineers, DevSecOps practitioners, and infrastructure teams who need to understand and prevent common Terraform misconfigurations in multi-cloud environments.

Value Proposition

TerraGoat offers a safe, controlled environment to practice cloud security testing without risking real infrastructure, with comprehensive multi-cloud coverage and real-world vulnerability patterns that mirror actual production misconfigurations.

Overview

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

Use Cases

Best For

  • Training teams on cloud security misconfigurations
  • Testing policy-as-code frameworks like Checkov
  • Developing secure Terraform coding practices
  • Practicing infrastructure vulnerability detection
  • Building DevSecOps training programs
  • Evaluating cloud security scanning tools

Not Ideal For

  • Production deployments or environments with sensitive resources, as the README explicitly warns against it due to intentionally vulnerable configurations.
  • Teams using exclusively non-Terraform IaC tools like CloudFormation or Pulumi, since it's Terraform-specific and part of a separate series for other tools.
  • Organizations with strict cloud budget constraints for training, as deploying multiple stacks incurs real costs from AWS, Azure, or GCP resources.
  • Projects needing out-of-the-box compliant or secure infrastructure, as all configurations are designed to demonstrate misconfigurations without remediation guidance.

Pros & Cons

Pros

Multi-Cloud Coverage

Supports AWS, Azure, and GCP with dedicated Terraform configurations, allowing comprehensive cross-cloud security training as shown in the separate setup sections for each provider.

Real-World Vulnerability Examples

Includes common misconfigurations like public databases and unencrypted storage, evidenced by the auto-generated scan results table listing over 100 specific security issues.

Policy-as-Code Integration

Designed to test frameworks like Checkov and Bridgecrew, with badges and references in the README, making it practical for tool evaluation and DevSecOps workflows.

Structured Deployment Guides

Provides step-by-step instructions for deploying and destroying stacks across all clouds, including scripts for managing multiple environments, as detailed in the Getting Started sections.

Cons

Vendor-Promotional Bias

Heavily promotes Bridgecrew's commercial tools and Checkov, which may limit impartial training for teams using alternative security scanning solutions.

No Remediation Guidance

Focuses on identifying vulnerabilities but lacks instructions or examples for fixing them, as seen in the scan results table that only lists issues without correction steps.

Setup Complexity for Novices

Requires pre-configuration of cloud backends (e.g., S3 buckets, storage accounts) and CLI tools, which can be a barrier for those new to Terraform or cloud infrastructure.

Real Cloud Cost Implications

Deploying vulnerable stacks uses actual paid cloud resources, risking unexpected expenses if not carefully managed or destroyed promptly after training.

Frequently Asked Questions

Quick Stats

Stars1,302
Forks5,819
Contributors0
Open Issues5
Last commit1 year ago
CreatedSince 2020

Tags

#aws-security#security-training#azure-security#azure#policy-as-code#terraform#infrastructure-as-code#devsecops#gcp#gcp-security#aws#cloud-security

Built With

T
Terraform

Links & Resources

Website

Included in

DevSecOps1.7k
Auto-fetched 17 hours ago

Related Projects

Kubernetes GoatKubernetes Goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Stars5,725
Forks1,033
Last commit3 months ago
Bad SSLBad SSL

:lock: Memorable site for testing clients against bad SSL configs.

Stars3,032
Forks204
Last commit1 month ago
cicd-goatcicd-goat

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Stars2,279
Forks414
Last commit2 years ago
WrongSecretsWrongSecrets

Vulnerable app with examples showing how to not use secrets

Stars1,451
Forks591
Last commit4 days ago
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub