基础设施即代码的静态分析工具,可在构建时检测跨Terraform、Kubernetes、CloudFormation和容器镜像的云配置错误、漏洞和机密信息。
Checkov 是一个用于基础设施即代码(IaC)的静态代码分析工具,同时也是用于镜像和开源包的软件组成分析(SCA)工具。
它扫描使用 Terraform、Terraform 计划、Cloudformation、AWS SAM、Kubernetes、Helm charts、Kustomize、Dockerfile、Serverless、Bicep、OpenAPI、ARM 模板 或 OpenTofu 配置的云基础设施,并使用基于图的扫描检测安全与合规配置错误。
它执行 软件组成分析(SCA)扫描,即对开源包和镜像进行常见漏洞与暴露(CVE)扫描。
Checkov 还为 Prisma Cloud 应用程序安全 提供支持,这是一个以开发者优先的平台,在整个开发生命周期中将云安全编码化并简化流程。Prisma Cloud 能够在云资源和基础设施即代码文件中识别、修复并防止配置错误。
CLI 中的扫描结果

Jenkins 中的定时扫描结果

要安装 pip,请遵循官方文档```sh pip3 install checkov
某些环境(例如Debian 12)可能要求您在虚拟环境中安装Checkov```sh
# Create and activate a virtual environment
python3 -m venv /path/to/venv/checkov
cd /path/to/venv/checkov
source ./bin/activate
# Install Checkov with pip
pip install checkov
# Optional: Create a symlink for easy access
sudo ln -s /path/to/venv/checkov/bin/checkov /usr/local/bin/checkov
或者使用 Homebrew (macOS或Linux)```sh brew install checkov
### 启用 bash 自动补全```sh
source <(register-python-argcomplete checkov)
如果你通过 pip3 安装了 checkov```sh pip3 install -U checkov
或通过 Homebrew```sh
brew upgrade checkov
checkov --directory /user/path/to/iac/code
或者一个特定的文件或多个文件```sh
checkov --file /user/tf/example.tf
或者```sh checkov -f /user/cloudformation/example1.yml -f /user/cloudformation/example2.yml
或者一个 terraform plan 文件的 json 格式```sh
terraform init
terraform plan -out tf.plan
terraform show -json tf.plan > tf.json
checkov -f tf.json
Note: terraform show output file tf.json will be a single line.
For that reason all findings will be reported line number 0 by Checkov```sh
check: CKV_AWS_21: "Ensure all data stored in the S3 bucket have versioning enabled"
FAILED for resource: aws_s3_bucket.customer
File: /tf/tf.json:0-0
Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/s3-policies/s3-16-enable-versioning
如果你已经安装了 `jq`,你可以使用以下命令将 JSON 文件转换为多行格式:```sh
terraform show -json tf.plan | jq '.' > tf.json
扫描结果会更加用户友好。```sh checkov -f tf.json Check: CKV_AWS_21: "Ensure all data stored in the S3 bucket have versioning enabled" FAILED for resource: aws_s3_bucket.customer File: /tf/tf1.json:224-268 Guide: https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/s3-policies/s3-16-enable-versioning