IaC and Dockerfile checks
Infrastructure-as-code files in a scanned repository are checked in the same scan job as the source code.
What is routed to the IaC checker
| File | Typical content |
|---|---|
*.tf | Terraform |
*.yaml, *.yml | Kubernetes manifests, CloudFormation templates |
*.json | CloudFormation templates and other JSON configuration |
Dockerfile, Dockerfile.*, *.dockerfile | Container build files |
Each file has a short per-file time limit, so one pathological file cannot stall the scan.
What it checks
For Kubernetes manifests, checks look for the misconfigurations that recur in workload definitions: privileged containers and privilege escalation, host namespaces, added Linux capabilities, sensitive host paths and Docker socket mounts, hard-coded credentials, wildcard RBAC rules, cleartext protocols and mutable image tags. Dockerfiles are checked for build hygiene. Findings appear with the other scan results, with file and line.
Limits worth knowing
- Helm charts are not rendered. Templates are read as files; values are not substituted.
- Not supported: Bicep, Pulumi programs and Kustomize builds.
- Separate from the posture rules. IaC checks use their own rule set. They are not the same rules the cloud posture (CSPM) engine evaluates against running resources, so a template result and a runtime result are not guaranteed to agree.
- The IaC checker ships inside the scanner image. Ask us for its current rule list against your templates before relying on a specific check.
To check running Kubernetes clusters rather than their manifests, see Container Security.