Feature Request: Terraform Source Code Scanning within Approval Policies

We need the ability to scan and validate Terraform source code within Spacelift approval policies to enforce security guardrails. Specifically, we want to prevent (not just detect) the usage of potentially dangerous Terraform providers before plans are executed.

Currently, approval policies do not have visibility into the underlying Terraform source code, limiting our ability to enforce provider-level security controls.

WorkaroundA before_plan hook script to scan Terraform files for dangerous provider usage and fail the run if violations are detected could be used.
ProblemThis workaround solution could however be bypassed by overwriting mount files. Plan policies cannot be used as a prevention guardrail as the run needs to be blocked before the plan is executed.

Please authenticate to join the conversation.

Upvoters
Status

👀 In Review

Board

💡 Feature Requests

Tags

Policies

Date

About 2 hours ago

Subscribe to request

Get notified by email when there are changes.