
Aurea is an open-source, AI-powered platform that secures infrastructure-as-code (IaC) across Terraform, Kubernetes, Docker, and Ansible. It integrates with CI/CD pipelines to scan for misconfigurations, detect vulnerabilities, enforce policies, and provide actionable remediation guidance. With predictive AI, collaboration tools, and enterprise-grade governance, Aurea ensures that infrastructure is secure, compliant, and resilient from development to deployment. https://gitlab.com/Roxanne_Ardary/aurea/
Golden Standards for IaC Security
Aurea is a fully open-source, AI-powered Infrastructure-as-Code security specification designed to provide continuous security analysis throughout the software development and infrastructure deployment lifecycle.
Aurea analyzes infrastructure definitions, identifies vulnerabilities and misconfigurations, evaluates security and compliance policies, provides AI-assisted remediation, and integrates directly into CI/CD and GitOps workflows.
Aurea is designed as a modular security system. Core modules provide the foundational security capabilities required by the specification. Optional plugin modules extend Aurea with additional infrastructure formats, cloud providers, compliance frameworks, AI systems, integrations, reporting systems, and specialized security capabilities.
Aurea is designed around local-first operation, vendor neutrality, explainable AI, least privilege, zero-trust principles, human oversight, reproducibility, and airtight service isolation.
Aurea consists of independently defined modules with clear interfaces and responsibilities.
Core modules provide essential Aurea functionality.
Optional plugin modules extend Aurea without requiring changes to the core security engine.
Modules should communicate through documented interfaces and should not require unnecessary coupling.
Aurea should support local execution whenever practical.
Security analysis should not require sending infrastructure code, credentials, secrets, or security findings to an external service.
External services should be optional integrations rather than mandatory dependencies.
Aurea must default to restrictive security settings.
Unsafe functionality must require explicit authorization.
High-impact actions must require explicit policy authorization and, where configured, human approval.
Every Aurea service, module, plugin, integration, and AI agent should receive only the permissions required to perform its assigned function.
Aurea services must not implicitly trust one another.
Authentication, authorization, and capability validation should occur at service boundaries.
Aurea must maintain strict isolation between services, plugins, AI agents, evaluation environments, credentials, and target infrastructure.
Security boundaries must be enforced by the execution environment and policy engine rather than relying solely on AI instructions.
The IaC Analysis Module provides the foundational analysis engine for Infrastructure-as-Code.
The Security Rules Module provides deterministic security detection.
The Secrets Security Module identifies potentially exposed credentials and sensitive information.
The module must prevent discovered secrets from being unnecessarily exposed in logs, reports, AI prompts, or external integrations.
The Dependency and Supply Chain Module evaluates dependencies associated with infrastructure.
The Risk Intelligence Module evaluates and prioritizes security findings.
The AI Security Analysis Module provides AI-assisted infrastructure security analysis.
AI-generated findings must remain distinguishable from deterministic security findings.
The AI Agent Module provides controlled AI agents for Aurea security workflows.