IaC Testing
Compare 186 iac testing tools to find the right one for your needs
π Subcategories
π§ Tools
Compare and find the best iac testing for your needs
ControlMonkey
A platform for automating and governing Terraform at scale.
Kubescape
An open-source Kubernetes security platform for risk analysis, security compliance, and misconfiguration scanning.
Infracost
A tool that shows cloud cost estimates for Terraform projects.
Infracost
A tool that shows cloud cost estimates for IaC changes, helping engineers understand the cost impact of their work.
Spacelift
A specialized CI/CD platform for IaC that provides policy-as-code, state management, and collaboration features.
Scalr
A Terraform automation platform that provides a hierarchical structure for managing environments, credentials, and variables.
Infracost
A tool that shows cloud cost estimates for infrastructure changes before they happen, integrating with CI/CD.
env0
An automation platform for IaC that enables self-service, governance, and cost management for Terraform and Terragrunt.
env0
An IaC platform for managing cloud environments with governance and cost control.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that unifies policy enforcement across the stack.
env0
An IaC automation platform that provides governance, cost management, and self-service capabilities for Terraform, Terragrunt, and other IaC tools.
Spacelift
A CI/CD platform for IaC that helps you manage and automate your infrastructure deployments.
Kubescape
An open-source Kubernetes security posture management tool that scans for misconfigurations and vulnerabilities.
env0
An IaC platform for managing and governing cloud environments.
Datree
A CLI tool for preventing misconfigurations in Kubernetes manifests by running automated checks.
Spacelift
A CI/CD platform for IaC with drift detection and policy as code.
Spacelift
A specialized CI/CD and management platform for Terraform, Pulumi, and other IaC tools, with a focus on policy and collaboration.
Datree
A CLI tool that runs automated checks on Kubernetes configuration files to ensure they follow policies and best practices.
CloudQuery
An open-source tool to build a cloud asset inventory and query it with SQL.
Infracost
A CLI tool and API that shows cloud cost estimates for Terraform projects, helping developers see the cost impact of their changes.
Kyverno
A policy engine designed for Kubernetes that can validate, mutate, and generate configurations using policies.
Styra DAS
An enterprise management plane for Open Policy Agent (OPA) that helps operationalize policy as code.
env0
An automation platform for IaC that includes policy-as-code and cost management features.
Snyk IaC
An IaC security tool that finds and fixes misconfigurations in cloud native application infrastructure.
Scalr
A Terraform automation and collaboration platform with built-in policy-as-code and governance features.
Open Policy Agent (OPA)
An open source, general-purpose policy engine that unifies policy enforcement across the stack.
Scalr
A Terraform automation and collaboration platform with a hierarchical model for policy and workspace management.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used to enforce policies on Terraform plans.
Scalr
A Terraform automation platform that provides an alternative to Terraform Cloud with features like hierarchical environments.
Checkov
An open-source static analysis tool for scanning Infrastructure as Code (IaC) files for misconfigurations.
Firefly
A platform for cloud asset management, IaC codification, and drift detection.
Wiz
A comprehensive cloud security platform that includes IaC scanning as part of its broader capabilities.
Wiz
A leading CNAPP that provides full-stack visibility and IaC scanning.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Snyk IaC
A developer-focused security tool that scans IaC files for misconfigurations and provides context and remediation advice.
Trivy
A versatile security scanner that finds vulnerabilities, IaC misconfigurations, and secrets in various targets.
Orca Security
An agentless cloud security platform that includes shift-left capabilities like IaC security scanning.
Orca Security
A comprehensive cloud security platform with IaC scanning.
Datadog Cloud Security Management
A cloud security solution from Datadog that includes IaC scanning.
Terraform Cloud
The official managed service from HashiCorp for running Terraform, providing collaboration, governance, and automation features.
Snyk Infrastructure as Code
A developer-focused security platform that includes IaC scanning and drift detection.
Prisma Cloud (by Palo Alto Networks)
A comprehensive CNAPP that includes IaC scanning, cloud security posture management, and workload protection.
Terraform Cloud
HashiCorp's managed service for Terraform, providing state management, collaboration, and governance features.
Snyk IaC
A developer-first security platform that helps you find and fix misconfigurations in your IaC files.
Snyk IaC
Find and fix security issues in IaC files.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform code.
tfsec
An open-source static analysis tool that checks Terraform code for security misconfigurations and compliance violations.
SonarQube
A leading static analysis platform that supports IaC scanning for Terraform, CloudFormation, Kubernetes, and more.
Checkov
A static code analysis tool for infrastructure as code.
HashiCorp Sentinel
An embeddable policy-as-code framework that integrates with the HashiCorp Enterprise products.
Terraform Cloud
HashiCorp's managed service offering for using Terraform in production.
Snyk Infrastructure as Code
A developer-focused tool for finding and fixing security misconfigurations in IaC files.
Terrascan
An open-source static code analyzer for IaC that helps detect security vulnerabilities and compliance violations.
TFLint
A linter focused on finding possible errors, best practice deviations, and enforcing naming conventions in Terraform code.
Trivy
A versatile security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in containers, IaC, and more.
Lacework
A CNAPP that uses data and automation to secure cloud environments.
Azure Policy
A service in Azure that you use to create, assign, and manage policies for your Azure resources.
Prisma Cloud (Bridgecrew)
A comprehensive cloud security platform that includes IaC scanning, drift detection, and compliance monitoring.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Terrascan
An open-source static code analyzer that scans IaC for security vulnerabilities and compliance violations.
Lightlytics
A cloud security and operations platform that simulates changes and detects drift to prevent downtime and misconfigurations.
AccuKnox
A comprehensive security platform for cloud-native applications and infrastructure.
JupiterOne
A platform for cyber asset attack surface management.
Infracost
Shows cloud cost estimates for Terraform.
Styra Declarative Authorization Service (DAS)
An enterprise management plane for Open Policy Agent (OPA).
Datree
A policy enforcement solution for Kubernetes that helps you prevent misconfigurations in your manifests.
Fugue
A cloud security platform that helps you manage the entire lifecycle of your cloud infrastructure, from code to cloud.
Lightspin
A cloud security platform that provides contextual risk analysis.
Wiz
A cloud security platform that provides visibility and risk context across the entire cloud stack.
Orca Security
An agentless cloud security platform for workload and data protection, CSPM, and more.
Fugue
A cloud security posture management (CSPM) tool for ensuring continuous compliance.
Kion
A cloud enablement platform for governance, automation, and financial management.
Conftest
A utility to help you write tests against structured configuration data using the Rego language from Open Policy Agent.
Lacework
A cloud security platform that uses data and automation to drive better security outcomes.
Brainboard
A visual cloud solution to design, deploy, and manage cloud infrastructures.
Snyk IaC
Find and fix security issues in your IaC configurations.
Datadog Cloud Security Management
A security and compliance solution within the Datadog platform that includes IaC scanning.
Trivy
A comprehensive security scanner that finds vulnerabilities, misconfigurations, secrets, and SBOMs in a wide range of targets.
Pulumi CrossGuard
A policy-as-code framework for Pulumi that allows you to enforce policies on your infrastructure using familiar programming languages.
Bridgecrew
A cloud security platform that helps you find and fix security and compliance issues in your cloud infrastructure.
Snyk Infrastructure as Code
Finds and fixes misconfigurations in Terraform, CloudFormation, Kubernetes, and ARM templates.
tfsec
A static analysis tool for Terraform code to spot potential security issues.
Ansible security automation
Use Ansible to automate your security processes.
Lacework
A cloud security platform that provides IaC security, CSPM, CWPP, and threat detection.
Checkov
An open-source static analysis tool for scanning infrastructure as code (IaC) files for misconfigurations.
Checkmarx IaC Security
A commercial IaC security solution from Checkmarx that includes the open-source KICS engine.
Pulumi
An IaC platform that lets you use familiar programming languages to provision and manage cloud infrastructure.
Terrascan
An open-source static code analysis tool for IaC.
tfsec
A static analysis tool for finding security issues in Terraform code.
Chef InSpec
An open-source testing framework for infrastructure with a human-readable language for specifying compliance, security, and policy requirements.
GitLab Ultimate
A comprehensive DevOps platform with integrated IaC security scanning.
Prisma Cloud by Palo Alto Networks
A comprehensive cloud security platform that includes IaC scanning, CSPM, CWPP, and more.
Chef InSpec
An open-source framework for testing and auditing your applications and infrastructure.
Checkov
A static code analysis tool for infrastructure-as-code.
KubeLinter
A linter for Kubernetes that checks for best practices and security issues.
Prisma Cloud by Palo Alto Networks
A comprehensive CNAPP that includes IaC scanning and drift detection.
Bridgecrew
A cloud security platform that includes IaC scanning and drift detection, now part of Palo Alto Networks.
Accurics
A cloud security platform that provides security and governance for the full cloud native stack.
AWS CloudFormation Drift Detection
A native AWS service for detecting changes made to stack resources outside of CloudFormation.
KICS
An open-source IaC static analysis tool by Checkmarx that finds security vulnerabilities, compliance issues, and misconfigurations.
KICS
An open-source static analysis tool from Checkmarx that scans IaC for security vulnerabilities, compliance issues, and misconfigurations.
Tenable.cs
A cloud-native security platform for the entire software lifecycle.
Checkov
An open-source static analysis tool for infrastructure as code.
Terrascan
An open-source static code analyzer for IaC that helps detect security and compliance violations.
KICS
An open-source static analysis tool that finds security vulnerabilities, compliance issues, and misconfigurations in IaC.
Terrascan
A static code analysis tool for IaC that helps you detect security vulnerabilities and compliance violations.
Chef InSpec
An open-source testing framework for infrastructure with a human-readable language for specifying compliance and security rules.
KICS
An open-source static analysis tool that finds security vulnerabilities, compliance issues, and infrastructure misconfigurations in IaC.
KICS
An open-source static analysis tool for IaC security.
Datadog Cloud Security Platform
A unified platform for security and observability, including IaC scanning.
Puppet Comply
A tool for assessing and remediating compliance issues.
Datadog Cloud Security Posture Management
A CSPM tool that detects misconfigurations, identifies threats, and helps manage compliance.
New Relic
An observability platform that includes infrastructure monitoring and security features.
tfsec
An open-source static analysis tool for finding security misconfigurations in Terraform.
New Relic Infrastructure
An infrastructure monitoring platform with configuration change tracking.
Datadog Cloud Security Platform
A security platform that combines observability and security for cloud environments.
Ansible-lint
A command-line tool for linting Ansible playbooks, roles, and collections.
KubeLinter
An open-source static analysis tool for Kubernetes manifests and Helm charts, checking for best practices.
cfn-lint
An AWS-supported open-source tool for linting and validating AWS CloudFormation templates.
Regula
An open-source tool that checks Terraform and CloudFormation templates for compliance with controls from frameworks like CIS.
Open Policy Agent (OPA)
An open-source, general-purpose policy engine that can be used to enforce policies on IaC.
OPA Gatekeeper
A Kubernetes admission controller that enforces policies created with Open Policy Agent (OPA).
Terrascan
An open-source static code analysis tool for IaC.
tfsec
An open-source static analysis tool that scans Terraform templates for security misconfigurations.
KICS
An open-source solution for static analysis of IaC, finding security vulnerabilities, compliance issues, and misconfigurations.
Steampipe
An open-source tool that maps cloud APIs to a PostgreSQL database, allowing for live SQL queries to detect drift.
Terragrunt
A CLI tool that provides extra helpers for keeping Terraform code DRY and managing multiple environments.
driftctl
An open-source CLI that tracks, alerts, and remedies infrastructure drift.
Yor
An open-source tool that automatically adds tags to IaC files, enriching them with context like git repository and commit details.
Terratag
An open-source CLI tool from env0 that helps manage and apply tags to all resources within a Terraform project.
Atlantis
An open-source tool for automating Terraform collaboration via pull requests, with drift detection capabilities.
Terratest
A Go library that provides patterns and helper functions for testing infrastructure, with first-class support for Terraform.
kitchen-terraform
A set of plugins for the Test Kitchen framework that enables integration and acceptance testing of Terraform code.
Digger
An open-source tool that runs Terraform/OpenTofu natively in your existing CI/CD system, enabling drift detection.
Resoto
An open-source tool for cloud asset inventory and search that can be used for drift detection.
conftest
A utility that uses the Rego language from Open Policy Agent to write tests against configuration files, including Terraform.
Regula
An open-source tool that evaluates Terraform and CloudFormation for security misconfigurations and compliance with standards like CIS.
Terratest
A Go library for writing automated tests for Infrastructure as Code, not a linter but a testing framework.
tflint
A linter for Terraform that focuses on checking for potential errors, best practices, and enforcing conventions.
Terradrift
A simple open-source tool that runs `terraform plan` across multiple directories to detect drift.
CloudQuery
An open-source tool that extracts, transforms, and loads cloud asset data into databases for analysis.
KubeDiff
An open-source CLI to detect differences between Kubernetes manifests and the running cluster state.
Terragrunt
A CLI tool that acts as a thin wrapper on Terraform to help manage complex projects by keeping code DRY and managing remote state.
Terragrunt
A tool to keep Terraform code DRY (Don't Repeat Yourself) by managing remote state and locking configurations.
Puppet-lint
A tool that validates Puppet code against the official Puppet language style guide.
driftctl
A CLI tool that scans cloud environments, compares them to your IaC state, and reports any unmanaged resources or drift.
Atlantis
An open-source, self-hosted application for automating Terraform via pull requests, enabling a GitOps workflow.
Cloud-Sploit
An open-source tool for scanning cloud environments for security risks.
Prowler
An open-source security tool for AWS, Azure, and GCP.
Scout Suite
An open-source tool for auditing the security of multi-cloud environments.
Pacu
An open-source exploitation framework for AWS.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
InSpec
An open-source testing framework for infrastructure with a human-readable language for specifying compliance, security, and policy requirements.
AWS CloudFormation Guard
A tool for checking CloudFormation templates for policy compliance.
Kitchen-Terraform
A Test Kitchen plugin for testing Terraform code.
Ansible Molecule
A framework for testing Ansible roles.
Steampipe
An open-source tool that lets you query cloud APIs using SQL.
CloudQuery
An open-source tool for extracting, transforming, and loading cloud infrastructure data into a database for analysis.
Regula
An open-source tool that evaluates infrastructure as code for security and compliance.
Regula
An open-source tool for checking IaC against security and compliance policies.
TFLint
A linter for Terraform that checks for possible errors, best practices, and naming conventions.
OpenTofu
An open-source fork of Terraform that is community-driven and managed by the Linux Foundation.
Terragrunt
A thin wrapper for Terraform that provides extra tools for keeping configurations DRY, working with multiple modules, and managing remote state.
TFLint
A static analysis tool for finding errors in Terraform code.
Terratest
A Go library for writing automated tests for your infrastructure code.
AWS CloudFormation Guard
An open-source policy as code tool for checking compliance of AWS CloudFormation templates and other structured data.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
cfn-lint
A linter for AWS CloudFormation templates.
Terratest
A Go library that provides patterns and helper functions for testing infrastructure.
Kubeval
A tool for validating Kubernetes configuration files against the official Kubernetes OpenAPI schemas.
Ansible Lint
A command-line tool for linting Ansible playbooks, roles, and collections.
KICS by Checkmarx
An open source static analysis tool for IaC.
Conftest
A utility to help you write tests against structured configuration files using the Rego language.
OPA Gatekeeper
A customizable admission webhook for Kubernetes that enforces policies executed by the Open Policy Agent (OPA).
CloudFormation Guard
An open-source tool for validating CloudFormation templates.
Prowler
A security tool for AWS, Azure, and GCP.
Cloud Custodian
An open-source tool that allows you to manage your cloud resources by defining policies in YAML.
Kube-score
A static analysis tool for Kubernetes that checks manifests for reliability and security best practices.
cfn-lint
An open-source linter from AWS for validating CloudFormation templates.
Terragrunt
A wrapper for Terraform that helps manage complex infrastructure by keeping code DRY and managing remote state.
Regula
A tool that evaluates IaC for security misconfigurations and compliance violations, powered by Open Policy Agent.
Terragrunt
A tool that helps you write more maintainable and reusable Terraform code.
Terratest
A Go library that provides patterns and helper functions for writing automated tests for infrastructure code.
Kyverno
A policy engine designed specifically for Kubernetes, allowing you to manage and validate configurations as policies.
TFLint
A linter for Terraform that focuses on best practices, style conventions, and detecting potential errors.
Atlantis
Automates Terraform via pull requests.