Skip to content

Conftest Overview

Conftest is a command-line tool designed to validate configuration files against security policies written in Rego, the policy language used by Open Policy Agent (OPA). It plays a critical role in DevSecOps workflows by enabling teams to enforce security and compliance rules across infrastructure-as-code (IaC) artifacts, such as Kubernetes manifests, Helm charts, and cloud provider templates. By integrating Conftest into CI/CD pipelines, teams can automate policy checks to catch misconfigurations early, reducing the risk of security vulnerabilities in production environments.

Overview of Conftest

Conftest operates by loading Rego policies and applying them to target configuration files. Each policy defines rules that describe acceptable configurations, and Conftest evaluates whether the files comply with these rules. For example, a policy might enforce that all Kubernetes pods run with non-root users or restrict the use of certain container images. If a file violates a policy, Conftest reports the issue, allowing developers to fix it before deployment.

Conftest supports multiple file formats, including:
- Kubernetes YAML/JSON manifests
- Helm charts
- Terraform configurations
- CloudFormation templates
- General-purpose JSON/YAML files

Its flexibility makes it a cornerstone of policy-driven infrastructure management, especially when paired with OPA for centralized policy enforcement.

Key Features

  • Policy-Based Validation: Leverages Rego policies to enforce security and compliance rules.
  • Multi-Format Support: Validates a wide range of configuration formats beyond Kubernetes.
  • CI/CD Integration: Easily embedded into pipelines for automated compliance checks.
  • Extensibility: Policies can be written and shared across teams, enabling consistent enforcement.

Use Cases

1. Validating Kubernetes Manifests

Conftest ensures Kubernetes resources adhere to security best practices. For example, a policy might check that all pods have securityContext.runAsNonRoot: true:

package k8s.pod.security

deny[msg] {
    input.kind == "Pod"
    not input.spec.securityContext
    msg := "Missing securityContext in Pod spec"
}

To test this policy against a manifest:

conftest test policies/k8s-pod.rego manifests/deployment.yaml

2. Enforcing Helm Chart Compliance

Conftest can validate Helm charts to ensure they follow security guidelines, such as avoiding hardcoded secrets or insecure image tags.

3. Cross-Platform Configuration Checks

Teams use Conftest to validate Terraform and CloudFormation templates for misconfigurations like overly permissive IAM roles or unencrypted S3 buckets.

Integration with CI/CD Pipelines

Conftest is typically invoked as part of a CI/CD pipeline to enforce policies before deployment. For example, in a GitHub Actions workflow:

- name: Validate Kubernetes manifests
  run: |
    conftest test policies/opa.rego manifests/*.yaml
    if [ $? -ne 0 ]; then
      echo "Policy violations found. Aborting deployment."
      exit 1
    fi

This ensures that all configuration files meet security criteria before reaching production.

Key takeaways

  • Conftest validates configuration files against Rego policies to enforce security and compliance.
  • It supports Kubernetes, Helm, Terraform, and other formats, enabling broad use cases.
  • Integration with CI/CD pipelines automates policy checks, reducing human error.
  • Conftest is a core tool in the OPA ecosystem, enabling policy-driven infrastructure management.
  • Policies are reusable and extensible, promoting consistency across teams and environments.