checkov - static analysis of infrastructure as code for security and compliance misconfigurations
checkov (-d DIR | -f FILE) [--framework terraform|terraform_plan] [-c IDS] [--skip-check IDS] [-o cli|json] [--compact] [--quiet] [--soft-fail]
Options you will use
-d, --directory DIR- scan every Terraform file under DIR
-f, --file FILE- scan one file; a plan in JSON (terraform show -json tfplan > tfplan.json) is scanned as terraform_plan
-c, --check IDS- run only these checks (comma separated)
--skip-check IDS- run everything except these
-o, --output FORMAT- cli (default), json, sarif, junitxml
--compact- do not print the code block of failed resources
--quiet- show failed checks only
--soft-fail- always exit 0 (report, but do not fail the pipeline)
--var-file FILE- Variable files to load in addition to the default files (terraform.tfvars, *.auto.tfvars). Only with --directory.
--framework LIST- Filter scan to run only on specific infrastructure as code frameworks: terraform, terraform_plan, kubernetes, helm, dockerfile, github_actions...
--skip-framework LIST- Filter scan to skip specific infrastructure as code frameworks.
-s, --soft-fail- Runs checks but always returns a 0 exit code.
--soft-fail-on LIST- Exits with a 0 exit code for the specified checks (IDs or severities).
--hard-fail-on LIST- Exits with a non-zero exit code for the specified checks.
--download-external-modules BOOL- Download external terraform modules from public git repositories and the registry.
--external-checks-dir DIR- Directory for custom checks to be loaded (repeatable).
--repo-root-for-plan-enrichment DIR- Directory containing the HCL code used to generate a given plan file (links plan findings back to the .tf lines).
--deep-analysis- Combine the plan file with the Terraform files for graph-based checks.
--config-file FILE- Path to a .checkov.yaml config file.
--create-config FILE- Write the current run's settings to a config file.
--baseline FILE- Use a .checkov.baseline file to report only results not in the baseline.
--create-baseline- Write a .checkov.baseline of the current failures (to adopt checkov on a legacy repo).
--output-file-path PATH- Name of the output folder to save the chosen output formats.
--list- List the IDs and titles of the checks.
--block-list-secret-scan LIST- List of files to filter out from the secret scanner.
--check IDS- Filter scan to run only on a specific check identifier (allowlist), comma separated.
Examples
$ checkov -d . --compactscan the configuration
$ terraform show -json tfplan > tfplan.json && checkov -f tfplan.jsonscan the planned values, with every variable resolved
Gotchas
- Suppress a check for one resource with a comment inside its block: #checkov:skip=CKV_AZURE_59:reason. The reason is printed as the suppress comment.
- Exit status: 1 when any check failed (unless --soft-fail), 0 otherwise.
Taught in
Try checkov in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.