CHECKOV
Static analysis tool for Infrastructure as Code. Scans Terraform, CloudFormation, Kubernetes, Helm, ARM, Serverless, and Dockerfiles.
INSTALLATION#
pip install checkov # Or: pipx install checkov # Or: brew install checkov
BASIC USAGE#
# Scan current directory checkov -d . # Scan specific file checkov -f main.tf checkov -f template.yaml checkov -f Dockerfile # Scan specific directory checkov -d ./terraform/ checkov -d ./cloudformation/
FRAMEWORK SELECTION#
checkov -d . --framework terraform checkov -d . --framework cloudformation checkov -d . --framework kubernetes checkov -d . --framework helm checkov -d . --framework dockerfile checkov -d . --framework arm checkov -d . --framework serverless checkov -d . --framework bicep checkov -d . --framework github_actions checkov -d . --framework gitlab_ci # Multiple frameworks checkov -d . --framework terraform,kubernetes,dockerfile # Skip frameworks checkov -d . --skip-framework dockerfile
OUTPUT OPTIONS#
checkov -d . -o cli # Default CLI output checkov -d . -o json # JSON checkov -d . -o junitxml # JUnit XML checkov -d . -o sarif # SARIF checkov -d . -o csv # CSV checkov -d . -o github_failed_only # GitHub annotations # Output to file checkov -d . -o json > results.json checkov -d . --output-file-path /path/to/output/
CHECK MANAGEMENT#
# List all checks
checkov --list
# Run specific checks
checkov -d . --check CKV_AWS_18 # Single check
checkov -d . --check CKV_AWS_18,CKV_AWS_19 # Multiple
# Skip specific checks
checkov -d . --skip-check CKV_AWS_18
checkov -d . --skip-check CKV_AWS_18,CKV_AWS_19
# Check by severity
checkov -d . --check-severity CRITICAL
checkov -d . --check-severity HIGH
# Inline skip (in Terraform)
resource "aws_s3_bucket" "example" {
#checkov:skip=CKV_AWS_18: Reason for skipping
bucket = "my-bucket"
}
COMMON CHECKS#
# AWS CKV_AWS_18 S3 bucket logging enabled CKV_AWS_19 S3 bucket encryption enabled CKV_AWS_20 S3 bucket public access block CKV_AWS_21 S3 bucket versioning enabled CKV_AWS_23 Security group unrestricted ingress CKV_AWS_24 Security group SSH open to world CKV_AWS_40 IAM password policy length CKV_AWS_41 IAM password policy reuse CKV_AWS_145 RDS encryption enabled CKV_AWS_149 EBS encryption enabled # Kubernetes CKV_K8S_1 Privileged container CKV_K8S_3 Root container CKV_K8S_8 Liveness probe CKV_K8S_9 Readiness probe CKV_K8S_20 Resource limits CKV_K8S_22 Read-only filesystem CKV_K8S_28 Capabilities drop ALL CKV_K8S_35 Secrets in environment variables # Dockerfile CKV_DOCKER_1 Root user CKV_DOCKER_2 Healthcheck CKV_DOCKER_3 Copy vs ADD
CI/CD INTEGRATION#
# Exit code checkov -d . --soft-fail # Always exit 0 checkov -d . --hard-fail-on CRITICAL # Fail only on critical checkov -d . --compact # Compact output # GitHub Actions # - uses: bridgecrewio/checkov-action@master # with: # directory: ./terraform/ # soft_fail: false
CUSTOM POLICIES#
# Python custom check
from checkov.terraform.checks.resource.base_resource_check import BaseResourceCheck
from checkov.common.models.enums import CheckResult, CheckCategories
class MyCustomCheck(BaseResourceCheck):
def __init__(self):
name = "Ensure custom requirement"
id = "CKV_CUSTOM_1"
supported_resources = ['aws_s3_bucket']
categories = [CheckCategories.GENERAL_SECURITY]
super().__init__(name=name, id=id, categories=categories,
supported_resources=supported_resources)
def scan_resource_conf(self, conf):
if conf.get("tags"):
return CheckResult.PASSED
return CheckResult.FAILED
# External checks directory
checkov -d . --external-checks-dir /path/to/custom/checks/
TIPS#
- Use --compact for CI/CD readability - Inline skip comments document accepted risk - --hard-fail-on CRITICAL for graduated enforcement - Combine with Trivy for runtime + config coverage - Custom Python checks for org-specific policies - SARIF output integrates with GitHub security tab - Supports Terraform plan files (checkov -f plan.json) - Use .checkov.yml for persistent configuration - Bridgecrew platform adds dashboard and drift detection - Scan early in CI/CD pipeline (shift-left)
CHECKOV CHEATSHEET
===================
Source: https://cheatsheet.johlem.net
Static analysis tool for Infrastructure as Code. Scans Terraform,
CloudFormation, Kubernetes, Helm, ARM, Serverless, and Dockerfiles.
INSTALLATION
-------------
pip install checkov
# Or: pipx install checkov
# Or: brew install checkov
BASIC USAGE
------------
# Scan current directory
checkov -d .
# Scan specific file
checkov -f main.tf
checkov -f template.yaml
checkov -f Dockerfile
# Scan specific directory
checkov -d ./terraform/
checkov -d ./cloudformation/
FRAMEWORK SELECTION
---------------------
checkov -d . --framework terraform
checkov -d . --framework cloudformation
checkov -d . --framework kubernetes
checkov -d . --framework helm
checkov -d . --framework dockerfile
checkov -d . --framework arm
checkov -d . --framework serverless
checkov -d . --framework bicep
checkov -d . --framework github_actions
checkov -d . --framework gitlab_ci
# Multiple frameworks
checkov -d . --framework terraform,kubernetes,dockerfile
# Skip frameworks
checkov -d . --skip-framework dockerfile
OUTPUT OPTIONS
---------------
checkov -d . -o cli # Default CLI output
checkov -d . -o json # JSON
checkov -d . -o junitxml # JUnit XML
checkov -d . -o sarif # SARIF
checkov -d . -o csv # CSV
checkov -d . -o github_failed_only # GitHub annotations
# Output to file
checkov -d . -o json > results.json
checkov -d . --output-file-path /path/to/output/
CHECK MANAGEMENT
------------------
# List all checks
checkov --list
# Run specific checks
checkov -d . --check CKV_AWS_18 # Single check
checkov -d . --check CKV_AWS_18,CKV_AWS_19 # Multiple
# Skip specific checks
checkov -d . --skip-check CKV_AWS_18
checkov -d . --skip-check CKV_AWS_18,CKV_AWS_19
# Check by severity
checkov -d . --check-severity CRITICAL
checkov -d . --check-severity HIGH
# Inline skip (in Terraform)
resource "aws_s3_bucket" "example" {
#checkov:skip=CKV_AWS_18: Reason for skipping
bucket = "my-bucket"
}
COMMON CHECKS
--------------
# AWS
CKV_AWS_18 S3 bucket logging enabled
CKV_AWS_19 S3 bucket encryption enabled
CKV_AWS_20 S3 bucket public access block
CKV_AWS_21 S3 bucket versioning enabled
CKV_AWS_23 Security group unrestricted ingress
CKV_AWS_24 Security group SSH open to world
CKV_AWS_40 IAM password policy length
CKV_AWS_41 IAM password policy reuse
CKV_AWS_145 RDS encryption enabled
CKV_AWS_149 EBS encryption enabled
# Kubernetes
CKV_K8S_1 Privileged container
CKV_K8S_3 Root container
CKV_K8S_8 Liveness probe
CKV_K8S_9 Readiness probe
CKV_K8S_20 Resource limits
CKV_K8S_22 Read-only filesystem
CKV_K8S_28 Capabilities drop ALL
CKV_K8S_35 Secrets in environment variables
# Dockerfile
CKV_DOCKER_1 Root user
CKV_DOCKER_2 Healthcheck
CKV_DOCKER_3 Copy vs ADD
CI/CD INTEGRATION
-------------------
# Exit code
checkov -d . --soft-fail # Always exit 0
checkov -d . --hard-fail-on CRITICAL # Fail only on critical
checkov -d . --compact # Compact output
# GitHub Actions
# - uses: bridgecrewio/checkov-action@master
# with:
# directory: ./terraform/
# soft_fail: false
CUSTOM POLICIES
-----------------
# Python custom check
from checkov.terraform.checks.resource.base_resource_check import BaseResourceCheck
from checkov.common.models.enums import CheckResult, CheckCategories
class MyCustomCheck(BaseResourceCheck):
def __init__(self):
name = "Ensure custom requirement"
id = "CKV_CUSTOM_1"
supported_resources = ['aws_s3_bucket']
categories = [CheckCategories.GENERAL_SECURITY]
super().__init__(name=name, id=id, categories=categories,
supported_resources=supported_resources)
def scan_resource_conf(self, conf):
if conf.get("tags"):
return CheckResult.PASSED
return CheckResult.FAILED
# External checks directory
checkov -d . --external-checks-dir /path/to/custom/checks/
TIPS
-----
- Use --compact for CI/CD readability
- Inline skip comments document accepted risk
- --hard-fail-on CRITICAL for graduated enforcement
- Combine with Trivy for runtime + config coverage
- Custom Python checks for org-specific policies
- SARIF output integrates with GitHub security tab
- Supports Terraform plan files (checkov -f plan.json)
- Use .checkov.yml for persistent configuration
- Bridgecrew platform adds dashboard and drift detection
- Scan early in CI/CD pipeline (shift-left)
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.