What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
- Current maintenance activity and release cadence under Tenable: confirm before recommending
- Kubernetes admission webhook feature: confirm it is still supported in the current codebase
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
Terrascan parses infrastructure definitions into a normalized intermediate representation and evaluates Rego policies against it. The normalization step is the design choice that matters: Terraform HCL, Kubernetes YAML, Helm charts, Kustomize output, CloudFormation, ARM templates and Dockerfiles all become the same shape of structured data, so a policy author works against one model rather than learning each format's quirks. Policies ship as Rego files paired with JSON metadata describing severity, category and the resource type they apply to.
Beyond the CLI it offers a server mode that exposes scanning over an API, and a Kubernetes admission webhook that applies the same policies at object creation time. That second mode is the more interesting capability, because it means the identical rule can gate a pull request and reject a resource at the cluster boundary without maintaining two policy sets. Output formats include JSON, YAML, XML, SARIF and JUnit.
Where it fits
Terrascan runs on a developer machine, as a pre-commit hook, and in CI against a repository of infrastructure code, before anything is applied. Platform or security engineering curates the policy set and decides the severity threshold that fails a build. The webhook deployment moves it into the cluster as a second checkpoint. As with any static IaC scanner, its usefulness depends on your definitions being readable from source: modules pulled from remote registries and values computed at apply time are outside what it can evaluate.
Strengths
- Single normalized model across formats means a custom policy written once can apply across Terraform and Kubernetes definitions.
- The Go binary is fast and dependency-free, which keeps CI steps short and installation trivial.
- The admission webhook lets you enforce the same policies at the cluster boundary that you check in the pipeline.
- Rego policies with structured metadata make it straightforward to filter, categorize and suppress rules systematically.
Limitations
- Project activity has been uneven since it moved under Tenable ownership, and rule content in cloud security ages quickly. Check current maintenance before making it a load-bearing control.
- Rego authorship is required for anything beyond the built-in policies, which limits customization to teams with that skill.
- Static analysis without plan awareness cannot resolve variables, remote module contents or computed values, which produces both misses and false positives on nontrivial Terraform.
Who it suits
Reasonable for teams that want a fast, single-binary IaC scanner with Rego policies and value the option of reusing those policies as an admission webhook. Teams that want the most actively maintained rule content, or that need plan-file awareness for accurate Terraform analysis, should compare it carefully against the alternatives before committing.
Used Terrascan? Recommend it under your own name and title.
Recommend this tool