terraform
Safeguard articles tagged "terraform" — guides, analysis, and best practices for software supply chain and application security.
34 articles
What Is IaC in Cyber Security? Risks, Scanning, and Best Practices
Infrastructure as Code turns your cloud setup into version-controlled files, which is powerful and dangerous in equal measure. Here is what IaC means for security teams.
tfsec to Trivy IaC: 2026 Migration Playbook
tfsec has been folded into Trivy for over a year and Aqua has stopped feature work on tfsec. We migrated three platforms in 2026 and documented what actually breaks.
GCP Terraform Provider Security Review
A security-focused review of the Google Terraform providers: provenance, authentication paths, state handling, and the misconfigurations that consistently produce incidents across the Google and Google-Beta provider ecosystem.
IaC Scanning Tools for Terraform and Beyond
IaC scanning tools catch misconfigured cloud resources before they're ever applied — the question is which ones actually understand Terraform's module graph instead of just its syntax.
How to scan Terraform for misconfigurations with Checkov
A hands-on guide to running Checkov against Terraform, triaging findings, writing custom policies, and blocking IaC misconfigurations before they merge.
How to encrypt a Terraform state file
A step-by-step guide to encrypting a Terraform state file using an S3 backend, KMS keys, and IAM controls to keep infrastructure secrets safe.
Terraform Provider Verification: Securing Your Infrastructure as Code Supply Chain
Terraform providers are plugins that execute with full access to your infrastructure credentials. Verifying their integrity is not optional.
Infrastructure as Code Security: Scanning Terraform, CloudFormation, and Kubernetes Manifests
IaC scanning catches misconfigurations before they reach production. This guide covers tools, techniques, and integration patterns for Terraform, CloudFormation, and Kubernetes.
Terraform Security Scanning: What to Scan, When, and How
A practical guide to integrating security scanning into your Terraform workflow without destroying developer productivity.
Securing Terraform Infrastructure as Code: A Practitioner's Guide
Your Terraform code defines your production infrastructure. If an attacker compromises your HCL files, state files, or provider plugins, they do not just get access — they get the keys to rebuild your entire environment on their terms.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.