1 of 53

THAILAND

2 of 53

AWS Infrastructure Pipeline with Terraform and Pre-commit Check

AWS Community Days 25 January 2025

3 of 53

�Navapon Tantechasa�DevSecOps Engineer

Abacus Digital

4 of 53

Agenda

  • Overview Problem can solve by Pre-commit check
  • Pre-commit components
  • Real-world Implementation with Pipeline

5 of 53

Start with why ?

6 of 53

7 of 53

Terraform Plan Outputs

8 of 53

Is it up to standard?

9 of 53

Trivy

10 of 53

Checkov

11 of 53

What we are missing

Operation

  • Enable Monitoring

Security

  • Enable IMDSV2
  • Enable EBS Encryptions
  • Attach IAM Role to instance

12 of 53

Problem Statement

  • Inconsistent code quality
  • Security vulnerabilities
  • No Awareness and Fast feedback Loops
  • Missing documentation
  • Manual review burden

13 of 53

Pre-commit Framework

14 of 53

15 of 53

What’s pre-commit

Git hook scripts are useful for identifying simple issues before submission to code review.

Before commit the code point out issue in code such as missing semicolons, trailing whitespace, and this allows a code reviewer to focus on the architecture of a change while not wasting time with trivial style nitpicks.

16 of 53

How to get start

17 of 53

How to configure

18 of 53

Before to make it work

19 of 53

How to make it work

20 of 53

Demo run Pre-commit

21 of 53

Essential Tools Deep Dive

22 of 53

Terraform fmt

Used to rewrite Terraform configuration files to a canonical format and style.

This command applies a subset of the along with other minor adjustments for readability.

23 of 53

Example

24 of 53

Terraform Validate

Validate runs checks that verify whether a configuration is syntactically valid and internally consistent, regardless of any provided variables or existing state.

25 of 53

Example

26 of 53

Terraform Docs

A utility to generate documentation from Terraform modules in various output formats.

27 of 53

Example

28 of 53

Demo run Terraform Docs

29 of 53

Terraform TFLint

TFLint performs automated checks on Terraform configurations to identify potential issues, errors, and violations of best practices.

TFLint helps maintain code quality, consistency, and reliability in Terraform projects

30 of 53

Setup Plugin

Create .tflint.hcl at Root

31 of 53

Install Plugin

32 of 53

33 of 53

Rule Available 700+

34 of 53

Trivy

Use Trivy to find vulnerabilities (CVE) & misconfigurations

Targets (what Trivy can scan):

- Container Image

- Filesystem

- Git Repository (remote)

- Virtual Machine Image

- Kubernetes

- AWS

Scanners (what Trivy can find there):

- OS packages and software dependencies in use (SBOM)

- Known vulnerabilities (CVEs)

- IaC issues and misconfigurations

- Sensitive information and secrets

- Software licenses

35 of 53

Demo run

36 of 53

Checkov

Checkov scans cloud infrastructure configurations to find misconfigurations before they're deployed

Checkov uses a common command line interface to manage and analyze infrastructure as code (IaC) scan results across platforms such as

  • Terraform,
  • CloudFormation,
  • Kubernetes,
  • Helm
  • Serverless framework.

37 of 53

Demo run

38 of 53

How Trivy and Checkov difference

39 of 53

Infracost

Infracost enables a shift-left approach for cloud costs by providing cost estimates for Terraform before deployment

40 of 53

Demo run

41 of 53

Git Hooks much more to explore

42 of 53

But this will not success�because …

43 of 53

It’s based on individual laptop

44 of 53

Real-world Implementation�Integration with Pipeline

45 of 53

Integration with GitHub Action or Other Pipeline

46 of 53

Secretless with OIDC Workflow

47 of 53

Define Code Owner�

Specific Reviewer for approve change

48 of 53

Create GitHub Rulesets for�

  • Check must Pass Before Merge
  • Require Approver

49 of 53

Fast Feedback Loops��

All recommended by tools, Terraform Plan Result or error put to PR Comment

50 of 53

51 of 53

Fast Feedback Loops��

52 of 53

Resource Example Available here

53 of 53

Q&A and Thankyou