AppSecNews
IaC Security Open source Established Verified profile

Checkov

by Prisma Cloud (Palo Alto Networks), originally Bridgecrew

A Python-based static analyzer that parses infrastructure as code into a graph and checks it against built-in and custom misconfiguration policies.

Visit checkov.io (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Checkov in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What it does

Checkov parses infrastructure definitions into an abstract representation and evaluates policies against it. For Terraform it reads HCL directly, resolves variables and module references where it can, and builds a resource graph so that a policy can reason about relationships, not just a single block. That graph model is what lets it answer questions like "is this S3 bucket referenced by a policy that makes it public" rather than only "does this block set an ACL attribute".

It ships a large set of built-in checks covering the major cloud providers, Kubernetes manifests, Helm charts, Dockerfiles, CloudFormation, Serverless framework definitions, ARM and Bicep templates. Policies are written either as Python classes or as YAML definitions that express attribute and connection conditions. Checkov also performs secret detection in scanned files and can consume a Terraform plan JSON file, which resolves values that are not knowable from source alone.

Where it fits

This is a pre-apply control. It runs on a developer laptop as a CLI or pre-commit hook, on pull requests through a CI job, and as a gate before terraform apply. Platform and security engineers usually own the policy set, while developers see the output. To get real value you need your IaC to be reasonably conventional: heavy use of dynamically generated resources, templating layers on top of Terraform, or values that only exist at apply time will limit what static parsing can see.

Strengths

  • The graph-based evaluation catches cross-resource issues that line-by-line linters miss.
  • Broad format coverage in one binary, so a single tool handles Terraform, Kubernetes, Helm and Dockerfiles.
  • Custom policies in YAML are approachable enough that a platform team can maintain them without writing Python.
  • Plan-file scanning closes much of the gap left by unresolvable variables.

Limitations

  • Noisy out of the box. The default policy set fires on things many teams accept, so expect an initial tuning pass with skip comments and suppression config.
  • Static parsing cannot resolve everything: remote modules, computed values and data sources produce blind spots that only plan scanning partially fixes.
  • Python startup and graph construction make large monorepo scans slow compared to Go-based alternatives.

Who it suits

A good default for teams standardizing Terraform and Kubernetes review in CI, particularly where one tool covering several formats beats several narrow ones. It suits organizations willing to invest in suppression hygiene and a curated policy baseline. Teams that want admission-time enforcement inside a cluster, or runtime detection, need a different tool alongside it.

Used Checkov? Recommend it under your own name and title.

Recommend this tool