Workload security
Assess infrastructure as code
Create a Secorvia IaC project, organize sources and revisions, and inspect resources and findings parsed from infrastructure code.
Reviewed
Before you start
Select a connected cloud account and have an infrastructure-code source you are authorized to assess. The current UI lists Terraform, CloudFormation, ARM, Bicep, Helm, and Kustomize.
Create an IaC project
Open IaC Security. Choose Cloud Account, enter Project Name, and optionally add a description. Create a project that corresponds to a repository, service, or environment your team can own.
Add a source
Open Project Detail, enter a Source Name such as prod-network-terraform, and choose Create. Keep source names specific enough to distinguish different stacks within the project.
Add and assess a revision
Use the source/revision controls shown for your project to supply the supported input and trigger a scan. Follow the live form for format and size constraints; these may depend on the deployment. Check that a revision exists before expecting parsed resources.
Review resources and findings
Read the project’s Revisions and Resources, then use View IaC Findings. Trace each issue to the source revision before editing the infrastructure definition. Reassess the updated revision after the change.
Where you are now
IaC findings are associated with a project and revision rather than being confused with the configuration of a running resource.
WHEN SOMETHING LOOKS OFF
A few things to check
No resources parsed yet
Check that a revision was supplied and a scan was triggered.
No revisions uploaded
Finish the source’s revision workflow before looking for parsed-resource results.
PUT IT INTO PRACTICE
Make your next move in Secorvia.
Open the app and follow along with your own organization.