< ciso
brief />
Tag Banner

All news with #terraform tag

19 articles

AWS Control Tower AFT adds plan-only customization

🛠️ AFT now supports plan-only customization runs that let administrators preview Terraform changes without applying them. This update enables safe pre-rollout validation, drift detection, and integration with CI/CD review workflows across all AFT-supported Terraform distributions. The feature is available in all Regions where AWS Control Tower Account Factory for Terraform is supported; see the AFT documentation and 1.22.0 release notes for setup details.
read more →

Jade Sleet Compromises Indian IT Firm via DevOps Lure

🛡️ SentinelOne attributes a campaign by the North Korean-linked group Jade Sleet to the compromise of an India-based IT services provider, using macOS backdoors FLATROOF and ROOFDECK. The attackers employed job-interview and coding project lures with weaponized Terraform lock files to trick developers into fetching malicious modules. FLATROOF uses Telegram for C2 and data theft, while ROOFDECK leverages the Nostr protocol for decentralized C2 and persistent, signed command execution. The incident underscores the growing risk to developer endpoints and supply chain vectors.
read more →

Architecting a Secure Landing Zone in EUSC

🔒 This post explains how to design a secure, scalable landing zone for the AWS European Sovereign Cloud (aws-eusc), a partitioned AWS environment operated within the EU. It covers account structure and governance, identity as IaC, centralized logging to a SIEM, data protection, perimeter and network design, CI/CD and artifact distribution, and incident response. The guidance maps to the AWS Security Reference Architecture and the AWS Well-Architected Framework, and highlights which behaviors are partition boundaries versus configurable choices.
read more →

Coder registry compromise delivered malicious Terraform modules

🔒 Coder disclosed that an attacker gained access to its Cloudflare-backed registry infrastructure and added unauthorized IPs that served a tampered copy of the project's package registry. Between 07:35 UTC and 21:45 UTC on August 31, some requests were routed to attacker-controlled servers that delivered modified Terraform modules containing credential-stealing code. The malicious modules searched for a wide range of secrets and exfiltrated data to a lookalike domain; Coder advises rotating affected secrets, examining logs, and purging cached packages prior to upgrading to patched releases.
read more →

IAM Policy Autopilot adds Terraform plan support

🔧 IAM Policy Autopilot now accepts Terraform plan files to generate baseline IAM policies. The open source tool, launched at re:Invent 2025, deterministically analyzes a plan to produce scoped policies that reference specific resource ARNs where possible. This capability complements existing Terraform-aware analysis and addresses the most requested feature since launch. IAM Policy Autopilot runs locally at no additional cost.
read more →

AWS Console-to-Code Expands to 32 Services

🚀 AWS Console-to-Code now supports 26 additional services and adds cross-region and cross-browser-tab action recording. This expands coverage from 6 to 32 services, helping developers, DevOps, and cloud architects convert manual console workflows into repeatable infrastructure as code (IaC). Actions are consolidated across regions and tabs so complex multi-region deployments retain context. Available today in all commercial AWS Regions.
read more →

SageMaker Unified Studio now supports Terraform

🔧 Amazon SageMaker Unified Studio now supports Terraform provisioning via the open-source terraform-aws-sagemaker-unified-studio module. Platform teams can deploy domains through version-controlled templates and integrate SageMaker Unified Studio into existing infrastructure-as-code pipelines. The module manages domain infrastructure and IAM roles, includes sub-modules for blueprints and projects, and uses the Terraform AWS Cloud Control Provider.
read more →

Amazon Neptune adds CloudFormation for global DBs

📣 Amazon Neptune now supports AWS CloudFormation for provisioning and managing Neptune global databases using the new AWS::Neptune::GlobalCluster resource type. You can define multi-region graph database topology as code, automate deployments, store configurations in source control, and integrate with CI/CD pipelines. Neptune global databases offer a single read-write primary and up to five read-only secondaries across Regions for low-latency reads, disaster recovery, and data residency. This capability is available in all Regions where Neptune global databases are supported.
read more →

Pattern-Based Policy as Code for Governing IaC on AWS

🔒 This AWS Security blog post outlines a pattern-based approach to policy as code, using Open Policy Agent (OPA) in CI/CD pipelines to validate Terraform plan JSON before deployment. It organizes checks around recurring control intents—required metadata, allowed configuration, exposure restriction, protection enforcement, and privilege constraint—to simplify review and maintenance. The article includes examples for S3 secure transport, VPC security group exposure, and IAM trust policy constraints, and describes artifact retention and phased rollout best practices.
read more →

IAM Policy Autopilot Adds Java and Terraform Support

🔧 IAM Policy Autopilot now analyzes Java applications and cross-references Terraform definitions to produce more precise IAM policies. The open-source tool, introduced at re:Invent 2025, already supported Python, TypeScript, and Go, and is available at no additional cost for local use. By resolving resource ARNs from Terraform, generated policies can avoid broad wildcard permissions and better enforce least-privilege. This update speeds policy creation and reduces time spent troubleshooting access issues.
read more →

AWS Storage Gateway Terraform Modules Add AL2023 Support

🔒 AWS updated its Storage Gateway Terraform modules to deploy gateways on Amazon Linux 2023, improving security, reliability, and IaC consistency. The modules support all gateway types—Amazon S3 File Gateway, Tape Gateway, and Volume Gateway—in both Amazon EC2 and VMware environments. EC2 deployments now enforce IMDSv2 by default to mitigate credential theft and SSRF, and support optional Elastic IP association and simplified Active Directory integration. The update also prevents unexpected gateway replacements during routine Terraform operations.
read more →

AWS Transfer Family Terraform Module Enables Web Apps

🔧 The AWS Transfer Family Terraform module now supports provisioning Transfer Family web apps, offering a branded, managed web portal for users to browse, upload, and download data in Amazon S3. The module centralizes deployment with federated authentication via AWS IAM Identity Center and fine-grained permissions using S3 Access Grants. An included end-to-end example covers Identity Center user and group assignment, Access Grants setup, web app configuration, and CloudTrail auditing.
read more →

Shifting Left at Enterprise Scale for Cloudflare Governance

🔐 Cloudflare describes how its Customer Zero team moved internal production account management from manual dashboard changes to a centralized Infrastructure as Code model to reduce human error and accelerate secure change. The effort uses Terraform, an Atlantis-driven CI/CD pipeline, and a custom tfstate-butler backend to securely manage state at scale. Policy enforcement relies on Open Policy Agent Rego policies executed through Conftest on every merge request, with warnings or deny gates and a formal exceptions workflow.
read more →

Google Application Design Center Now Generally Available

🛠️ Google's Application Design Center is now generally available, delivering a visual, canvas-style, AI-assisted environment to design and deploy Terraform-backed application templates. It pairs Gemini Cloud Assist with opinionated Terraform components to generate deployable infrastructure patterns and architecture diagrams. Integrated with App Hub and Cloud Hub, it makes applications discoverable, observable, and manageable, while supporting BYO-Terraform, GitOps, and enterprise governance to accelerate platform engineering and developer self-service.
read more →

AWS Tag Policies: Validate and Enforce Required Tags

🔒 AWS Organizations Tag Policies introduces Reporting for Required Tags, a validation check that ensures IaC deployments include mandatory tags. You define a tag policy specifying required keys and enable validation for CloudFormation, Terraform, or Pulumi workflows. Validation is implemented by activating the AWS::TagPolicies::TaggingComplianceValidator Hook in CloudFormation, adding plan-time checks in Terraform, or enabling the aws-organizations-tag-policies policy pack in Pulumi. The feature is available via the AWS Management Console, AWS CLI, and AWS SDK in supported Regions.
read more →

AWS Transfer Family Terraform Module Adds Malware Scanning

🛡️ AWS has updated the Transfer Family Terraform module to support automated malware scanning workflows for files transferred to S3. The module provisions GuardDuty S3 Protection–based scan pipelines, dynamic routing based on results, and threat notifications in a single deployment. It preserves folder structure, allows granular S3 prefix targeting, and helps ensure only verified clean files reach applications and data lakes.
read more →

AWS Transform auto-generates Landing Zone network YAML

☁️ AWS Transform for VMware can now automatically convert VMware network environments into Landing Zone Accelerator (LZA)-compatible YAML network configurations that can be directly imported and deployed via LZA. Building on existing IaC output formats such as CloudFormation, AWS CDK, and Terraform, this capability reduces manual re-creation of network settings, lowers the risk of configuration errors, and accelerates migration timelines while aligning deployments with enterprise security and compliance standards.
read more →

AWS Transform Adds Terraform Module Generation for VMware

🔁 AWS Transform for VMware now generates reusable Terraform modules from discovered VMware network definitions, complementing existing AWS CloudFormation and CDK outputs. The feature converts source network configurations into modular, customizable infrastructure code that fits into current deployment pipelines. It is available in all Regions where the service is offered and helps teams preserve operational consistency during migrations. By producing Terraform modules, the service enables reuse of Terraform-based workflows, reduces manual configuration effort, and supports teams that prefer Terraform for network automation.
read more →

AWS Transfer Family Adds Terraform SFTP Connector Support

🚀 The AWS Transfer Family Terraform module now supports provisioning SFTP connectors to transfer files between Amazon S3 and remote SFTP servers. Announced 2025-08-27, the addition builds on existing Terraform support for SFTP server endpoints and enables programmatic provisioning of connectors, dependencies, and customizations in a single IaC deployment. The module includes end-to-end examples to automate transfers on schedules or event triggers, reducing manual configuration and improving repeatability, security, and scale.
read more →