Tool integration

terraform-compliance Integration Guide

BDD-style compliance testing for Terraform plans using Gherkin

Get a Free API Key

Integrate terraform-compliance with Vulnetix. Write BDD-style compliance tests in Gherkin for your Terraform plans and export JSON results for upload to Vulnetix.

TerraformCLI toolJSON

Install & scan

$ # Install with pip
pip install terraform-compliance

# Or via uv
uv run --with terraform-compliance terraform-compliance --help
$ # Generate Terraform plan JSON first
terraform plan -out=tfplan
terraform show -json tfplan > plan.json

# Run compliance tests
terraform-compliance   -f ./compliance-tests/   -p plan.json   --junit-xml compliance-results.xml

Run terraform-compliance in CI

Scan on every push and upload the report as a workflow artifact:

- name: Generate Terraform plan
  run: |
    terraform init
    terraform plan -out=tfplan
    terraform show -json tfplan > plan.json

- name: Run compliance tests
  run: |
    pip install terraform-compliance
    terraform-compliance -f ./compliance-tests/ -p plan.json --junit-xml compliance-results.xml

- name: Upload results to Vulnetix
  run: vulnetix upload --file compliance-results.xml

How Vulnetix compares: better together

Vulnetix does not replace terraform-compliance. Keep running it. Vulnetix sits on top of terraform-compliance (and every other scanner you already own) turning disconnected tool outputs into one prioritised, fixable queue.

terraform-compliance is strongest at its core category and also carries features in Secret Scanning, just as Vulnetix spans categories.

CapabilityVulnetixterraform-compliance
Security coverage
SAST (static code analysis)Built-in rules + Semgrep augmentation
SCA / dependencies40+ ecosystems, transitive graph
DAST (dynamic testing)~ Ingests DAST results; no native dynamic engine
Container & imageImage CVEs, base image, Dockerfile
IaC / misconfigurationTerraform, k8s, CloudFormationCore: BDD/Gherkin compliance testing of terraform plans, enforces encryption, security-group, tagging, VPC/subnet and resource-restriction policies
Secret scanning1,000+ rules, source + binary + git history~ Can author BDD scenarios asserting no plaintext secrets/passwords in resource config, but has no dedicated secret-detection engine
Cloud / CSPMCloud-posture findings, compliance tab
Mobile (MAST)~ Ingests mobile scanner output; no native mobile engine
License complianceSPDX, copyleft/AGPL/SSPL policy
SBOM generationCycloneDX 1.7 + SPDX 2.3, cosign-signable
Malware / supply-chainDe-duplicated corpus + install-time firewall (25+ registries)
Network / infra vuln~ Ingests network scanner output; no native network scanner
FuzzingIngests fuzzing crashes; no native fuzzer
Pentest / bug bountyIngests pentest/bug-bounty findings; not a testing service
The Vulnetix orchestration layer
Cross-scanner dedup & one queue (ASPM)Correlates every scanner into one prioritised queue with ownership routing
Exploit-intel prioritisationEPSS, CISA KEV, Coalition ESS, CWSS, Vulnetix LEV
Reachability analysisTree-sitter + CVEAffected; direct/transitive/semantic
Versioned VEX + audit trailImmutable OpenVEX/CycloneDX, cosign-signable
Safe Harbour autofixResolves + applies the nearest safe version
End-of-life policyFlags/blocks past-EOL runtimes & packages
SSVC / risk-based policySSVC v2 + CISA/FedRAMP/Essential-8 presets

✓ full · ~ partial · ✗ not covered

What terraform-compliance does well

Where Vulnetix adds to it: terraform-compliance excels at expressing custom org policy as readable Gherkin against a Terraform plan, but is scoped to IaC compliance assertions you write yourself. Vulnetix adds a full native scanner stack (SAST, SCA, container, secrets, cloud, SBOM) plus built-in IaC misconfig rules, and consolidates terraform-compliance results into a cross-scanner deduped queue with EPSS/KEV prioritisation, versioned VEX and SSVC. It layers on top, it does not replace the team's Gherkin policy suite.

No migration, no rip-and-replace. terraform-compliance keeps doing what it does best; Vulnetix adds the orchestration, exploit-intelligence prioritisation and remediation layer built for the way AppSec works today.

Centralise terraform-compliance results in Vulnetix

Upload terraform-compliance JSON output to the Vulnetix platform to deduplicate findings, prioritise them with EPSS, CISA KEV and Coalition ESS exploit intelligence, and track remediation across every scanner in a single queue.

terraform-compliance documentation ↗  ·  Source repository ↗

Wire terraform-compliance into your CI/CD pipeline →