IaC Security Guide: Terraform

You're reading Gomboc's field guide to securing infrastructure as code. The following resources are tactical guides created specifically for platform engineers, devsecops, and cloud security practitioners to leverage in their day to day work.

More guides are on the way! Check back here soon!
More guides are on the way! Check back here soon!
Key benefits

What is Terraform?

Terraform is an open-source infrastructure as code (IaC) tool developed by HashiCorp. It allows you to define, provision, and manage cloud and on-premises infrastructure resources using a declarative configuration language.

Declarative Language & State Management

Maintains a state file to track and manage resources and uses HashiCorp Configuration Language (HCL) for defining infrastructure

Modularity

Supports reusable modules for better code organization and scalability

Multi-Cloud Support

Terraform can manage resources across various cloud providers and services

Reduce your backlog to zero

Make CSPM findings a thing of the past. Integrate Gomboc AI and immediately get remediations pushed to your CI/CD pipeline so DevOps teams can skip the busywork. Never fall out of compliance again. Never deal with cloud misconfigurations. Get to #BacklogZero today.