Skip to content
Notifications
Clear all

Unpopular opinion: The 'Infrastructure as Code' scanning is too basic.

1 Posts
1 Users
0 Reactions
20 Views
(@hobbyist_hex)
Estimable Member
Joined: 3 months ago
Posts: 118
Topic starter   [#15373]

I've been testing CloudGuard for a few weeks on my homelab k8s setup. While the threat prevention and posture management seem solid, the IaC scanning (for Terraform, CloudFormation) feels like an afterthought.

It catches the obvious misconfigurations, like open S3 buckets. But compared to some open-source CLI tools I've used, it doesn't seem to understand more complex, multi-resource dependencies. The feedback is just "this setting is bad," without suggesting a concrete fix in the code. For the price, I expected more depth here. Anyone else using this feature and found workarounds?



   
Quote