Terraform IaC
Terraform IaC
Analyze Terraform configuration and state for cryptographic keys, certificates, and algorithms
Applies to:
Terraform HCLTerraform StateKeys & CertificatesInfrastructure-as-Code
Overview
The Terraform IaC source analyzes Terraform HCL configuration and state files for cryptographic configuration. It surfaces the keys, certificates, and algorithms declared or recorded in your infrastructure-as-code so you can assess their quantum exposure before they reach production.
What It Scans
| Item | Details |
|---|---|
| HCL configuration | Cryptographic configuration declared in Terraform HCL |
| State files | Cryptographic material recorded in Terraform state |
| Keys & certificates | Keys and certificates referenced or generated by the configuration |
| Algorithms | Algorithms and parameters with quantum risk assessment |
When to Use
📝
Shift-Left for Infra
Catch quantum-vulnerable cryptographic configuration in IaC before deployment
🔍
State Auditing
Review cryptographic material captured in Terraform state files
How to Run
Run a Terraform IaC scan from the Cockpit scan wizard:
1
Open Run a Scan
In the Cockpit, go to Run a Scan.
2
Select the source
In Step 1 (Source), choose Terraform IaC.
3
Provide the configuration
Point the scan at your Terraform configuration and state, then start the scan and review the findings.