Onam Security

IaC and Dockerfile checks

Infrastructure-as-code files in a scanned repository are checked in the same scan job as the source code.

What is routed to the IaC checker

FileTypical content
*.tfTerraform
*.yaml, *.ymlKubernetes manifests, CloudFormation templates
*.jsonCloudFormation templates and other JSON configuration
Dockerfile, Dockerfile.*, *.dockerfileContainer build files

Each file has a short per-file time limit, so one pathological file cannot stall the scan.

What it checks

For Kubernetes manifests, checks look for the misconfigurations that recur in workload definitions: privileged containers and privilege escalation, host namespaces, added Linux capabilities, sensitive host paths and Docker socket mounts, hard-coded credentials, wildcard RBAC rules, cleartext protocols and mutable image tags. Dockerfiles are checked for build hygiene. Findings appear with the other scan results, with file and line.

Limits worth knowing

  • Helm charts are not rendered. Templates are read as files; values are not substituted.
  • Not supported: Bicep, Pulumi programs and Kustomize builds.
  • Separate from the posture rules. IaC checks use their own rule set. They are not the same rules the cloud posture (CSPM) engine evaluates against running resources, so a template result and a runtime result are not guaranteed to agree.
  • The IaC checker ships inside the scanner image. Ask us for its current rule list against your templates before relying on a specific check.

To check running Kubernetes clusters rather than their manifests, see Container Security.