{"repo":"bridgecrewio/terragoat","free":true,"listed":false,"github":"https://github.com/bridgecrewio/terragoat","clone":"git clone https://github.com/bridgecrewio/terragoat.git","description":"TerraGoat is Bridgecrew's \"Vulnerable by Design\" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.","language":"HCL","stars":1305,"topics":["terraform","aws-security","cloud-security","goat","azure-security","gcp-security","devsecops"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"TerraGoat - Vulnerable Terraform Infrastructure TerraGoat is Bridgecrew's \"Vulnerable by Design\" Terraform repository. TerraGoat is Bridgecrew's \"Vulnerable by Design\" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments. Table of Contents Introduction Getting Started AWS Azure GCP Contributing Support Introduction TerraGoat was built to enable DevSecOps design and implement a sustainable misconfiguration prevention strategy. It can be used to test a policy-as-code framework like Bridgecrew & Checkov, inline-linters, pre-commit hooks or other code scanning methods. TerraGoat follows the tradition of existing Goat projects that provide a baseline training ground to practice implementing secure development best practices for cloud infrastructure. Important notes Where to get help: the Bridgecrew Community Slack Before you proceed please take a not of these warning: :warning: TerraGoat creates intentionally vulnerable AWS resources into your account. DO NOT deploy TerraGoat in a production environment or alongside any sensitive AWS resources. Requirements Terraform 0.12 aws cli azure cli To prevent vulnerable infrastructure from arriving to production see: Bridgecrew & checkov, the open source static analysis tool for infrastructure as code. Getting started AWS Setup Installation (AWS) You can deploy multiple TerraGoat stacks in a single AWS account using the par","default_branch":null,"files":null,"tree":[],"storefront":"/r/bridgecrewio","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/bridgecrewio/terragoat/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}