Conftest Overview
Conftest is a command-line tool designed to validate configuration files against security policies written in Rego, the policy language used by Open Policy Agent (OPA). It plays a critical role in DevSecOps workflows by enabling teams to enforce security and compliance rules across infrastructure-as-code (IaC) artifacts, such as Kubernetes manifests, Helm charts, and cloud provider templates. By integrating Conftest into CI/CD pipelines, teams can automate policy checks to catch misconfigurations early, reducing the risk of security vulnerabilities in production environments.
Overview of Conftest¶
Conftest operates by loading Rego policies and applying them to target configuration files. Each policy defines rules that describe acceptable configurations, and Conftest evaluates whether the files comply with these rules. For example, a policy might enforce that all Kubernetes pods run with non-root users or restrict the use of certain container images. If a file violates a policy, Conftest reports the issue, allowing developers to fix it before deployment.
Conftest supports multiple file formats, including:
- Kubernetes YAML/JSON manifests
- Helm charts
- Terraform configurations
- CloudFormation templates
- General-purpose JSON/YAML files
Its flexibility makes it a cornerstone of policy-driven infrastructure management, especially when paired with OPA for centralized policy enforcement.
Key Features¶
- Policy-Based Validation: Leverages Rego policies to enforce security and compliance rules.
- Multi-Format Support: Validates a wide range of configuration formats beyond Kubernetes.
- CI/CD Integration: Easily embedded into pipelines for automated compliance checks.
- Extensibility: Policies can be written and shared across teams, enabling consistent enforcement.
Use Cases¶
1. Validating Kubernetes Manifests¶
Conftest ensures Kubernetes resources adhere to security best practices. For example, a policy might check that all pods have securityContext.runAsNonRoot: true:
package k8s.pod.security
deny[msg] {
input.kind == "Pod"
not input.spec.securityContext
msg := "Missing securityContext in Pod spec"
}
To test this policy against a manifest:
2. Enforcing Helm Chart Compliance¶
Conftest can validate Helm charts to ensure they follow security guidelines, such as avoiding hardcoded secrets or insecure image tags.
3. Cross-Platform Configuration Checks¶
Teams use Conftest to validate Terraform and CloudFormation templates for misconfigurations like overly permissive IAM roles or unencrypted S3 buckets.
Integration with CI/CD Pipelines¶
Conftest is typically invoked as part of a CI/CD pipeline to enforce policies before deployment. For example, in a GitHub Actions workflow:
- name: Validate Kubernetes manifests
run: |
conftest test policies/opa.rego manifests/*.yaml
if [ $? -ne 0 ]; then
echo "Policy violations found. Aborting deployment."
exit 1
fi
This ensures that all configuration files meet security criteria before reaching production.
Key takeaways¶
- Conftest validates configuration files against Rego policies to enforce security and compliance.
- It supports Kubernetes, Helm, Terraform, and other formats, enabling broad use cases.
- Integration with CI/CD pipelines automates policy checks, reducing human error.
- Conftest is a core tool in the OPA ecosystem, enabling policy-driven infrastructure management.
- Policies are reusable and extensible, promoting consistency across teams and environments.