Ask HN:您是如何为 Terraform/IaC 进行威胁建模的?

1 分•作者: PotatoFy•3 个月前
最近我花了很多时间研究基础设施安全,特别是复杂的漏洞如何成为标准编码和 Terraform 配置的涌现属性。 我目前正在构建一个工具,该工具可以解析 IaC(基础设施即代码)以自动绘制 STRIDE 威胁模型,但在深入研究之前,我想问问团队在实际工作中是如何处理这个问题的……
查看原文
I&#x27;ve been spending a lot of time lately looking at infrastructure security, specifically how complex vulnerabilities are often an emergent property of standard coding and Terraform configurations.<p><pre><code> I&#x27;m currently building a tool that parses IaC to automatically map out STRIDE threat models, but before I go too far down the rabbit hole, I wanted to ask how teams are handling this in the real world...</code></pre>