Skip to main content

Terraform IaC

Applies to:
Terraform HCLTerraform StateKeys & CertificatesInfrastructure-as-Code

Overview​

The Terraform IaC source analyzes Terraform HCL configuration and state files for cryptographic configuration. It surfaces the keys, certificates, and algorithms declared or recorded in your infrastructure-as-code so you can assess their quantum exposure before they reach production.

What It Scans​

ItemDetails
HCL configurationCryptographic configuration declared in Terraform HCL
State filesCryptographic material recorded in Terraform state
Keys & certificatesKeys and certificates referenced or generated by the configuration
AlgorithmsAlgorithms and parameters with quantum risk assessment

When to Use​

📝

Shift-Left for Infra

Catch quantum-vulnerable cryptographic configuration in IaC before deployment

🔍

State Auditing

Review cryptographic material captured in Terraform state files

How to Run​

Run a Terraform IaC scan from the Cockpit scan wizard:

1

Open Run a Scan

In the Cockpit, go to Run a Scan.

2

Select the source

In Step 1 (Source), choose Terraform IaC.

3

Provide the configuration

Point the scan at your Terraform configuration and state, then start the scan and review the findings.