Book Image

Terraform Cookbook - Second Edition

By : Mikael Krief
4.5 (2)
Book Image

Terraform Cookbook - Second Edition

4.5 (2)
By: Mikael Krief

Overview of this book

Imagine effortlessly provisioning complex cloud infrastructure across various cloud platforms, all while ensuring robustness, reusability, and security. Introducing the Terraform Cookbook, Second Edition - your go-to guide for mastering Infrastructure as Code (IaC) effortlessly. This new edition is packed with real-world examples for provisioning robust Cloud infrastructure mainly across Azure but also with a dedicated chapter for AWS and GCP. You will delve into manual and automated testing with Terraform configurations, creating and managing a balanced, efficient, reusable infrastructure with Terraform modules. You will learn how to automate the deployment of Terraform configurations through continuous integration and continuous delivery (CI/CD), unleashing Terraform's full potential. New chapters have been added that describe the use of Terraform for Docker and Kubernetes, and explain how to test Terraform configurations using different tools to check code and security compliance. The book devotes an entire chapter to achieving proficiency in Terraform Cloud, covering troubleshooting strategies for common issues and offering resolutions to frequently encountered errors. Get the insider knowledge to boost productivity with Terraform - the indispensable guide for anyone adopting Infrastructure as Code solutions.
Table of Contents (20 chapters)
16
Other Books You May Enjoy
17
Index

Using tfsec to analyze the compliance of Terraform configuration

In the previous recipe, we learned how to use a custom tool to perform an HCL check on the Terraform configuration without running terraform plan and exporting the output of the plan command.

In this recipe, we will learn how to use the popular tool tfsec to analyze the compliance of the Terraform configuration.

tfsec (its documentation is available here: https://aquasecurity.github.io/tfsec/v1.28.1/) is an open source static analysis tool for Terraform code. It is designed to detect security issues, policy violations, and other potential problems in Terraform code, and provides a set of rules that can be used to scan code for these issues.

tfsec works by analyzing the Abstract Syntax Tree (AST) of Terraform code. This allows it to identify security issues and policy violations based on the structure of the code, without executing the code or connecting to any external services.

Some of the benefits of...