Awesome AWS
Section: Security · Terraform static analysis, verifies security best practices.
Entry
Appears in 7 awesome lists
Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
Section: Security · Terraform static analysis, verifies security best practices.
Section: Security & Compliance · A static analysis tool for infrastructure as code - to prevent misconfigs at build time.
Section: Infrastructure as Code Analysis · Bridgecrew - Scan Terraform, AWS CloudFormation and Kubernetes templates for insecure configuration.
Section: Security · Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.
Section: Development · A static analysis tool for infrastucture as code (Terraform).
Section: Tools · Terraform static analysis tool for terraform>=0.12
Section: Security · Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages.
Set up a DIY/personal VPN in the cloud. It is a set of Ansible scripts that simplify the setup of a personal WireGuard and IPsec VPN, open-sourced by Trail of Bits. :green_circle:
🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…
A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.
🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.
🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…