Checkov, Trivy and tflint
Checkov, Trivy and tflint are static scanners: they read code and images and report misconfigurations, known vulnerabilities and mistakes before anything is deployed. The GCP Enterprise Baseline and the GCP blueprints run them on every commit through pre-commit and on every pull request in CI.
What it does
tflint lints OpenTofu code: syntax, unused declarations and, with a provider ruleset, invalid values such as a machine type that does not exist. Checkov checks infrastructure code against security policies, for example a bucket without uniform access or a cluster without network policy. Trivy scans infrastructure code for misconfigurations and container images for known vulnerabilities (CVEs) in OS packages and libraries. Each tool accepts in-line suppressions, and a suppression should say why.
How BuiltForProd uses it
| Tool | Version | Runs on | Where |
|---|---|---|---|
| tflint | 0.64.0, tflint-ruleset-google 0.40.0 | OpenTofu modules | pre-commit; the lint-and-scan job of each infrastructure plan.yml |
| Checkov | 3.3.19 (infrastructure), 3.3.22 (code repositories) | OpenTofu modules; workflows and Dockerfiles in the code repositories | pre-commit; the plan workflow through the pinned Checkov action |
| Trivy | trivy-action v0.36.0 in CI | OpenTofu modules (pre-commit); built images (CI) | pre-commit terraform_trivy; the ci.yml image scan of the code repositories |
Configuration. .tflint.hcl enables the terraform plugin with the recommended preset and the Google ruleset, and lints only the repository's own modules. .checkov.yaml scans the Terraform framework, skips .terragrunt-cache and .terragrunt-stack, and skips one check, CKV_TF_1, because every module is local. tflint is downloaded at a pinned version and checked against its release SHA-256 before it runs in CI.
Suppressions carry a reason. A finding that does not apply is skipped in the resource itself, with the reason on the same line, so a reviewer sees the exception where it is made. For example, the GKE cluster skips the Calico network-policy check because Dataplane V2 enforces NetworkPolicy itself, and the data lake skips legacy bucket access logs because Data Access audit logs record object access.
Image scans. The code repositories' ci.yml builds every image without pushing it and scans it with Trivy: fixable CRITICAL and HIGH findings in OS packages and libraries fail the pull request, and findings with no fix available are reported but do not block. Pushed images are scanned again by Artifact Analysis in the registry.
Terms you will see
| Term | Meaning |
|---|---|
| Ruleset | A tflint plugin of provider-specific rules, here for Google Cloud. |
| Check ID | The identifier of a Checkov policy, such as CKV_GCP_12. |
| In-line skip | A suppression comment on the resource, with its reason. |
ignore-unfixed | Trivy reports CVEs without a fix but does not fail on them. |
Where to read more
- GCP Enterprise Baseline overview for the repository layout.
- pre-commit for the hooks that run these tools locally.
- Policy as code for where static checks sit among the controls.