← All cheat sheets

CHECKOV

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

Static analysis tool for Infrastructure as Code. Scans Terraform,
CloudFormation, Kubernetes, Helm, ARM, Serverless, and Dockerfiles.

INSTALLATION#

pip install checkov
# Or: pipx install checkov
# Or: brew install checkov

BASIC USAGE#

# Scan current directory
checkov -d .

# Scan specific file
checkov -f main.tf
checkov -f template.yaml
checkov -f Dockerfile

# Scan specific directory
checkov -d ./terraform/
checkov -d ./cloudformation/

FRAMEWORK SELECTION#

checkov -d . --framework terraform
checkov -d . --framework cloudformation
checkov -d . --framework kubernetes
checkov -d . --framework helm
checkov -d . --framework dockerfile
checkov -d . --framework arm
checkov -d . --framework serverless
checkov -d . --framework bicep
checkov -d . --framework github_actions
checkov -d . --framework gitlab_ci

# Multiple frameworks
checkov -d . --framework terraform,kubernetes,dockerfile

# Skip frameworks
checkov -d . --skip-framework dockerfile

OUTPUT OPTIONS#

checkov -d . -o cli                         # Default CLI output
checkov -d . -o json                        # JSON
checkov -d . -o junitxml                    # JUnit XML
checkov -d . -o sarif                       # SARIF
checkov -d . -o csv                         # CSV
checkov -d . -o github_failed_only          # GitHub annotations

# Output to file
checkov -d . -o json > results.json
checkov -d . --output-file-path /path/to/output/

CHECK MANAGEMENT#

# List all checks
checkov --list

# Run specific checks
checkov -d . --check CKV_AWS_18             # Single check
checkov -d . --check CKV_AWS_18,CKV_AWS_19  # Multiple

# Skip specific checks
checkov -d . --skip-check CKV_AWS_18
checkov -d . --skip-check CKV_AWS_18,CKV_AWS_19

# Check by severity
checkov -d . --check-severity CRITICAL
checkov -d . --check-severity HIGH

# Inline skip (in Terraform)
resource "aws_s3_bucket" "example" {
  #checkov:skip=CKV_AWS_18: Reason for skipping
  bucket = "my-bucket"
}

COMMON CHECKS#

# AWS
CKV_AWS_18    S3 bucket logging enabled
CKV_AWS_19    S3 bucket encryption enabled
CKV_AWS_20    S3 bucket public access block
CKV_AWS_21    S3 bucket versioning enabled
CKV_AWS_23    Security group unrestricted ingress
CKV_AWS_24    Security group SSH open to world
CKV_AWS_40    IAM password policy length
CKV_AWS_41    IAM password policy reuse
CKV_AWS_145   RDS encryption enabled
CKV_AWS_149   EBS encryption enabled

# Kubernetes
CKV_K8S_1     Privileged container
CKV_K8S_3     Root container
CKV_K8S_8     Liveness probe
CKV_K8S_9     Readiness probe
CKV_K8S_20    Resource limits
CKV_K8S_22    Read-only filesystem
CKV_K8S_28    Capabilities drop ALL
CKV_K8S_35    Secrets in environment variables

# Dockerfile
CKV_DOCKER_1  Root user
CKV_DOCKER_2  Healthcheck
CKV_DOCKER_3  Copy vs ADD

CI/CD INTEGRATION#

# Exit code
checkov -d . --soft-fail                    # Always exit 0
checkov -d . --hard-fail-on CRITICAL        # Fail only on critical
checkov -d . --compact                      # Compact output

# GitHub Actions
# - uses: bridgecrewio/checkov-action@master
#   with:
#     directory: ./terraform/
#     soft_fail: false

CUSTOM POLICIES#

# Python custom check
from checkov.terraform.checks.resource.base_resource_check import BaseResourceCheck
from checkov.common.models.enums import CheckResult, CheckCategories

class MyCustomCheck(BaseResourceCheck):
    def __init__(self):
        name = "Ensure custom requirement"
        id = "CKV_CUSTOM_1"
        supported_resources = ['aws_s3_bucket']
        categories = [CheckCategories.GENERAL_SECURITY]
        super().__init__(name=name, id=id, categories=categories,
                        supported_resources=supported_resources)

    def scan_resource_conf(self, conf):
        if conf.get("tags"):
            return CheckResult.PASSED
        return CheckResult.FAILED

# External checks directory
checkov -d . --external-checks-dir /path/to/custom/checks/

TIPS#

  - Use --compact for CI/CD readability
  - Inline skip comments document accepted risk
  - --hard-fail-on CRITICAL for graduated enforcement
  - Combine with Trivy for runtime + config coverage
  - Custom Python checks for org-specific policies
  - SARIF output integrates with GitHub security tab
  - Supports Terraform plan files (checkov -f plan.json)
  - Use .checkov.yml for persistent configuration
  - Bridgecrew platform adds dashboard and drift detection
  - Scan early in CI/CD pipeline (shift-left)

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.