Workload security

Assess infrastructure as code

Create a Secorvia IaC project, organize sources and revisions, and inspect resources and findings parsed from infrastructure code.

Reviewed

Before you start

Select a connected cloud account and have an infrastructure-code source you are authorized to assess. The current UI lists Terraform, CloudFormation, ARM, Bicep, Helm, and Kustomize.

Create an IaC project

Open IaC Security. Choose Cloud Account, enter Project Name, and optionally add a description. Create a project that corresponds to a repository, service, or environment your team can own.

Add a source

Open Project Detail, enter a Source Name such as prod-network-terraform, and choose Create. Keep source names specific enough to distinguish different stacks within the project.

Add and assess a revision

Use the source/revision controls shown for your project to supply the supported input and trigger a scan. Follow the live form for format and size constraints; these may depend on the deployment. Check that a revision exists before expecting parsed resources.

Review resources and findings

Read the project’s Revisions and Resources, then use View IaC Findings. Trace each issue to the source revision before editing the infrastructure definition. Reassess the updated revision after the change.

Where you are now

IaC findings are associated with a project and revision rather than being confused with the configuration of a running resource.

WHEN SOMETHING LOOKS OFF

A few things to check

No resources parsed yet

Check that a revision was supplied and a scan was triggered.

No revisions uploaded

Finish the source’s revision workflow before looking for parsed-resource results.

PUT IT INTO PRACTICE

Make your next move in Secorvia.

Open the app and follow along with your own organization.

Open Secorvia