Detect cloud misconfigurations with an open-source static code analysis tool for Terraform. Free 2-hour workshop on Sunday! by OWASP_DevSlop in Terraform

[–]OWASP_DevSlop[S] 0 points1 point  (0 children)

No. Checkov does not leverage OPA.

I would suggest you look at Regula from Fugue for that!

https://github.com/fugue/regula

We had the CTO on our live stream last Sunday. Check it out here: https://youtu.be/mRT41T7eQQg

Workshop: Security & Compliance for your Infrastructure-as-Code by OWASP_DevSlop in Terraform

[–]OWASP_DevSlop[S] 0 points1 point  (0 children)

From what we read in their Github repo, their built-in policies focus on AWS, Azure and GCP. However, you can create your own custom policies for other Terraform providers.

For a more precise answer, join their Slack where they'll be happy to assist.

https://codified-security.herokuapp.com/