IaC Testing
Compare 153 iac testing tools to find the right one for your needs
π Subcategories
π§ Tools
Compare and find the best iac testing for your needs
ControlMonkey
An end-to-end Terraform automation platform with a focus on drift detection and remediation.
Kubescape
An open-source Kubernetes security platform for risk analysis, security compliance, and misconfiguration scanning.
Infracost
A tool that shows cloud cost estimates for Terraform projects.
Infracost
A tool that shows cloud cost estimates for IaC changes, helping engineers understand the cost impact of their work.
Spacelift
A CI/CD platform for Infrastructure as Code.
Scalr
A Terraform automation platform that provides a hierarchical structure for managing environments, credentials, and variables.
Infracost
A tool that shows cloud cost estimates for infrastructure changes before they happen, integrating with CI/CD.
env0
An automation platform for IaC that simplifies governance and collaboration, with drift detection.
env0
An automation platform for IaC that enables self-service, governance, and cost management for Terraform and Terragrunt.
Spacelift
A CI/CD platform for IaC that helps you manage and automate your infrastructure deployments.
env0
An IaC automation platform that provides governance, cost management, and self-service capabilities for Terraform, Terragrunt, and other IaC tools.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that unifies policy enforcement across the stack.
env0
An IaC platform for managing and governing cloud environments.
Spacelift
A specialized CI/CD and management platform for Terraform, Pulumi, and other IaC tools, with a focus on policy and collaboration.
Kubescape
An open-source Kubernetes security posture management tool that scans for misconfigurations and vulnerabilities.
Datree
A CLI tool for preventing misconfigurations in Kubernetes manifests by running automated checks.
Datree
A CLI tool that runs automated checks on Kubernetes configuration files to ensure they follow policies and best practices.
Spacelift
A sophisticated CI/CD platform for IaC that offers drift detection and automated remediation.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud asset data into databases for analysis.
env0
An automation platform for IaC that includes policy-as-code and cost management features.
Styra DAS
An enterprise management plane for Open Policy Agent (OPA) that helps operationalize policy as code.
Infracost
A CLI tool and API that shows cloud cost estimates for Terraform projects, helping developers see the cost impact of their changes.
Kyverno
A policy engine designed for Kubernetes.
Snyk IaC
An IaC security tool that finds and fixes misconfigurations in cloud native application infrastructure.
Scalr
A Terraform automation and collaboration platform with built-in policy-as-code and governance features.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used for enforcing policies on IaC.
Scalr
A Terraform automation and collaboration platform with a hierarchical model for policy and workspace management.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used to enforce policies on Terraform plans.
Scalr
A Terraform automation platform that provides hierarchical governance and self-service for developers.
Checkov
An open-source static analysis tool for scanning Infrastructure as Code (IaC) files for misconfigurations.
Firefly
A platform for cloud asset management, IaC adoption, and governance.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Wiz
A comprehensive CNAPP that includes IaC scanning as part of its cloud security solution.
Wiz
A comprehensive cloud security platform that includes IaC scanning as part of its broader capabilities.
Snyk IaC
A developer-focused security tool that scans IaC files for misconfigurations and provides context and remediation advice.
Trivy
A versatile security scanner that finds vulnerabilities, IaC misconfigurations, and secrets in various targets.
Orca Security
An agentless cloud security platform that includes shift-left capabilities like IaC security scanning.
Orca Security
An agentless CNAPP that provides security and compliance across the full cloud-native application lifecycle, including IaC scanning.
Terraform Cloud
The official managed service from HashiCorp for running Terraform, providing collaboration, governance, and automation features.
Datadog Cloud Security Management
A cloud security platform that includes IaC scanning, posture management (CSPM), and workload security (CWS).
Snyk Infrastructure as Code
A developer-focused security platform that includes IaC scanning and drift detection.
Prisma Cloud (by Palo Alto Networks)
A comprehensive CNAPP that includes IaC scanning, cloud security posture management, and workload protection.
Terraform Cloud
A managed service from HashiCorp that provides collaboration and automation features for Terraform.
Snyk IaC
An IaC security tool from Snyk that helps developers find and fix misconfigurations.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
Snyk IaC
Find and fix security issues in your IaC files.
tfsec
An open-source static analysis tool that checks Terraform code for security misconfigurations and compliance violations.
SonarQube
A leading static analysis platform that supports IaC scanning for Terraform, CloudFormation, Kubernetes, and more.
Checkov
An open-source static analysis tool for scanning IaC to find misconfigurations.
Terraform Cloud
HashiCorp's managed service offering for using Terraform in production.
Snyk Infrastructure as Code
A developer-focused tool for finding and fixing security misconfigurations in IaC files.
HashiCorp Sentinel
A policy as code framework from HashiCorp that integrates with its Enterprise products.
Terrascan
An open-source static code analyzer for IaC that helps detect security vulnerabilities and compliance violations.
TFLint
A linter focused on finding possible errors, best practice deviations, and enforcing naming conventions in Terraform code.
Lacework
A CNAPP that uses anomaly detection to secure cloud environments, with IaC security features to shift left.
Azure Policy
A service in Azure that you use to create, assign, and manage policies for your Azure resources.
Trivy
A versatile security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in containers, IaC, and more.
Prisma Cloud (Bridgecrew)
A comprehensive cloud security platform that includes IaC scanning, drift detection, and compliance monitoring.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Terrascan
An open-source static code analyzer that scans IaC for security vulnerabilities and compliance violations.
Infracost
Shows cloud cost estimates for Terraform.
Lightspin
A CNAPP acquired by Cisco that uses graph technology to find attack paths.
Wiz
An agentless cloud security platform that provides a full-stack view of risks.
Orca Security
An agentless cloud security platform that provides workload and data protection, CSPM, and more.
Lacework
A CNAPP that uses anomaly detection to identify threats and misconfigurations.
Ansible security automation
Use Ansible to automate your security processes.
Pulumi CrossGuard
A policy as code framework for the Pulumi IaC platform, allowing policies to be written in general-purpose languages.
Datadog Cloud Security Management
A security and compliance solution within the Datadog platform that includes IaC scanning.
tfsec
A static analysis tool for finding security issues in Terraform code.
Trivy
A vulnerability scanner for containers, IaC, and more.
Pulumi
An IaC platform that lets you use familiar programming languages to provision and manage cloud infrastructure.
Chef InSpec
An open-source framework for testing and auditing your applications and infrastructure.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Checkmarx IaC Security
A commercial IaC security solution from Checkmarx that includes the open-source KICS engine.
Checkov
A static code analysis tool for infrastructure-as-code.
Chef InSpec
An open-source framework for testing and auditing your applications and infrastructure.
tfsec
A static analysis tool for Terraform code to spot potential security issues.
Terrascan
An open-source static code analyzer for IaC that helps detect security and compliance issues.
Prisma Cloud by Palo Alto Networks
A comprehensive CNAPP that includes IaC scanning and drift detection.
KICS
An open-source static analysis tool from Checkmarx for finding security vulnerabilities in IaC.
KICS
An open-source static analysis tool from Checkmarx that scans IaC for security vulnerabilities, compliance issues, and misconfigurations.
AWS CloudFormation Drift Detection
A native AWS service for detecting changes made to stack resources outside of CloudFormation.
KICS
An open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in IaC.
Terrascan
An open-source static code analyzer for IaC that helps detect security and compliance violations.
Terrascan
A static code analysis tool for IaC that helps detect security vulnerabilities and compliance violations.
KICS
An open-source IaC scanning tool by Checkmarx that finds security vulnerabilities, compliance issues, and misconfigurations.
Checkov
A static code analysis tool for infrastructure as code (IaC) to find misconfigurations.
KICS
An open-source static analysis tool for IaC that finds security vulnerabilities, compliance issues, and infrastructure misconfigurations.
Chef InSpec
An open-source testing framework for infrastructure with a human-readable language for specifying compliance and security rules.
Puppet Comply
A tool for assessing and remediating compliance issues.
Datadog Cloud Security Posture Management
A CSPM tool that detects misconfigurations, identifies threats, and helps manage compliance.
New Relic
An observability platform that includes infrastructure monitoring and security features.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform.
Atlantis
An open-source, self-hosted application for automating Terraform via pull requests, enabling a GitOps workflow.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud asset data into databases for analysis.
OPA Gatekeeper
A Kubernetes admission controller that enforces policies created with Open Policy Agent (OPA).
driftctl
An open-source CLI that warns of infrastructure drifts and fills in the missing piece in your DevSecOps toolbox.
Terragrunt
A tool to keep Terraform code DRY (Don't Repeat Yourself) by managing remote state and locking configurations.
Puppet-lint
A tool that validates Puppet code against the official Puppet language style guide.
Ansible-lint
A command-line tool for linting Ansible playbooks, roles, and collections.
KubeLinter
An open-source static analysis tool for Kubernetes manifests and Helm charts, checking for best practices.
cfn-lint
An AWS-supported open-source tool for linting and validating AWS CloudFormation templates.
Regula
An open-source tool that checks Terraform and CloudFormation templates for compliance with controls from frameworks like CIS.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used to enforce policies on IaC.
tfsec
An open-source static analysis tool that scans Terraform templates for security misconfigurations.
KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Yor
An open-source tool that automatically adds tags to IaC files, enriching them with context like git repository and commit details.
Terrascan
An open-source static code analyzer for IaC that helps detect security issues.
Terratag
An open-source CLI tool from env0 that helps manage and apply tags to all resources within a Terraform project.
conftest
A utility that uses the Rego language from Open Policy Agent to write tests against configuration files, including Terraform.
Steampipe
An open-source tool that maps cloud APIs to a PostgreSQL database, allowing for live SQL queries.
Terragrunt
An open-source wrapper for Terraform that simplifies managing complex infrastructure.
kitchen-terraform
A set of plugins for the Test Kitchen framework that enables integration and acceptance testing of Terraform code.
Terratest
A Go library for writing automated tests for Infrastructure as Code, not a linter but a testing framework.
Regula
An open-source tool that evaluates Terraform and CloudFormation for security misconfigurations and compliance with standards like CIS.
driftctl
A CLI tool that scans cloud environments, compares them to your IaC state, and reports any unmanaged resources or drift.
Terragrunt
A CLI tool that acts as a thin wrapper on Terraform to help manage complex projects by keeping code DRY and managing remote state.
Atlantis
An open-source tool for automating Terraform via pull requests.
Regula
A tool that evaluates IaC for security misconfigurations and compliance violations, powered by Open Policy Agent.
Terratest
A Go library that provides patterns and helper functions for writing automated tests for infrastructure code.
Kyverno
A policy engine designed specifically for Kubernetes, allowing you to manage and validate configurations as policies.
TFLint
A linter for Terraform that focuses on best practices, style conventions, and detecting potential errors.
Conftest
A utility to help you write tests against structured configuration files using the Rego language.
Regula
A tool that evaluates IaC for security and compliance.
TFLint
A linter for Terraform that checks for errors, best practices, and naming conventions.
OPA Gatekeeper
A customizable admission webhook for Kubernetes that enforces policies executed by OPA.
AWS CloudFormation Guard
A tool for checking CloudFormation templates for policy compliance.
Terragrunt
A wrapper for Terraform that helps manage complex infrastructure by keeping code DRY and managing remote state.
Terratest
A Go library for writing automated tests for your infrastructure code.
Kitchen-Terraform
A Test Kitchen plugin for testing Terraform code.
Ansible Molecule
A framework for testing Ansible roles.
Steampipe
An open-source tool that lets you query cloud APIs using SQL.
CloudQuery
An open-source tool for extracting, transforming, and loading cloud infrastructure data into a database for analysis.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
KICS by Checkmarx
An open source static analysis tool for IaC.
cfn-lint
An open-source linter from AWS for validating CloudFormation templates.
Atlantis
Automates Terraform via pull requests.
CloudFormation Guard
An open-source tool for checking CloudFormation templates against policies.
Prowler
A security tool for AWS, Azure, and GCP.
Cloud Custodian
A rules engine for managing public cloud accounts.
AWS CloudFormation Guard
An open-source policy as code tool for checking compliance of AWS CloudFormation templates and other structured data.
Regula
An open-source tool for checking IaC against security and compliance policies.
Terratest
A Go library that provides patterns and helper functions for testing infrastructure, with first-class support for Terraform.
OpenTofu
An open-source fork of Terraform that is community-driven and managed by the Linux Foundation.
Terragrunt
A tool to keep your Terraform code DRY (Don't Repeat Yourself) and manage multiple environments.
TFLint
A linter for Terraform that checks for errors, best practices, and potential issues.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
cfn-lint
A linter for AWS CloudFormation templates.
Kubeval
A tool for validating Kubernetes configuration files against the official Kubernetes OpenAPI schemas.
Terratest
A Go library for writing automated tests for your infrastructure code.
Kube-score
A static analysis tool for Kubernetes that checks manifests for reliability and security best practices.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
tflint
A linter for Terraform that focuses on checking for potential errors, best practices, and enforcing conventions.