u/RoseSec_

SBOM for Infrastructure as Code

Is anyone generating SBOMs for their IaC repositories? Looking into the best way to accomplish this for compliance and curious if a tool that converts Terraform lockfiles to SPDX would be beneficial?

reddit.com
u/RoseSec_ — 1 day ago
▲ 2 r/devops

I just implemented Cloud Custodian across our environment with checks for unused IAM roles and users. What are your favorite use cases for the tool? Looking for cool ideas on how to use the tooling to increase security.

reddit.com
u/RoseSec_ — 17 days ago