I am giving a talk Wednesday, May 3rd at 10:35 AM ET, at HashiCorp HashiTalks Secure titled "Building end-to-end secure workflows for Terraform deployments, from code to runtime".
I am going to show how you can use the new open-source security scanner called cnspec from Mondoo to integrate into each stage of #terraform automation workflow including pre-plan, post-plan, and post-apply to test every change to ensure infrastructure meets compliance and business requirements.
I will be using the #okta Terraform provider as an example and we will build a policy that checks both the Terraform code and runtime environment by hitting Okta’s API directly.
The talk will wrap up by showing how the same workflow can be integrated into #githubactions. I will provide all of the code examples I share for anyone that wants to try this out.
So if you are interested in #securityautomation, #platformengineering, or #devsecops, come join me.
I hope to see you there!
https://lnkd.in/ghjb4zuV
https://cnspec.io