Ask HN:您是如何为 Terraform/IaC 进行威胁建模的?
1 分•作者: PotatoFy•3 个月前
最近我花了很多时间研究基础设施安全,特别是复杂的漏洞如何成为标准编码和 Terraform 配置的涌现属性。
我目前正在构建一个工具,该工具可以解析 IaC(基础设施即代码)以自动绘制 STRIDE 威胁模型,但在深入研究之前,我想问问团队在实际工作中是如何处理这个问题的……
查看原文
I've been spending a lot of time lately looking at infrastructure
security, specifically how complex vulnerabilities are often an
emergent property of standard coding and Terraform configurations.<p><pre><code> I'm currently building a tool that parses IaC to automatically map
out STRIDE threat models, but before I go too far down the rabbit
hole, I wanted to ask how teams are handling this in the real world...</code></pre>