Every vendor talks about "DevOps integration" and "shift-left security" now. Check Point is no different. Their marketing makes CloudGuard sound like a natural fit for CI/CD pipelines.
But I want to hear from teams who've actually wired it into a real production DevOps workflow. Not a POC, not a sandbox. Specifically:
* Does the Terraform provider actually keep up with the console features, or are you constantly forced to manual workarounds?
* How painful is the policy-as-code experience compared to something native like AWS Security Hub or open-source tools?
* What's the real latency impact on your deployment pipelines? Seconds or minutes?
* Is the cost model based on VPCs/Gateways a nightmare for dynamic, auto-scaling environments?
The datasheets are useless for this. Looking for concrete wins and, more importantly, the inevitable integration pitfalls and hidden management costs.
Trust but verify.