RELEASE and DEPLOY Phase
Static scan of Kubernetes manifest file or Helm chart
docker run -t -v $(pwd):/output bridgecrew/checkov -f /output/keycloak-deploy.yml -o json
# For Helm
docker run -t -v $(pwd):/output bridgecrew/checkov -d /output/ --framework helm -o jsonPre-deploy policy check Kubernete manifest YAML file
kube-bench for CIS scan
kubectl apply -f eks-job.yaml
kubectl logs kube-bench-pod-nameIaC scanning:
terraform init
terraform plan -out tf.plan
terraform show -json tf.plan | jq '.' > tf.json
checkov -f tf.jsonLast updated
