SlideShare a Scribd company logo
Anton Grübel, AWS DevOps Engineer
SHIFT LEFT
How to improve your security with
checkov before it’s going to
production
Me, Myself & I
● AWS Enthusiast
● Python Fan
● Open Source Contributor
● Playstation Gamer
● GitHub: gruebel
● PSN: anton-mai
About us
2017 Founded
100% AWS-focussed
20 Talents
33 AWS Certifications
1 AWS Competency
1 APN Ambassador
1 AWS Community Builder
What is Shift Left?
Shift Left is a practice intended to find and prevent defects early in the software
delivery process. The idea is to improve quality by moving tasks to the left as early
in the lifecycle as possible.
Kirstie Magowan (bmc)
Shift Left model
Shift Left security
IaC security tools
● cfn-nag
● terrascan
● KICS
● tfsec
● terraform-compliance
● AWS CloudFormation Guard
● checkov
Shift Left - How to improve your security with checkov before it’s going to production
checkov features
● Over 1000 built-in policies
● Supports Terraform (+ plan), CFN, ARM, Docker, Kubernetes, Helm, SLS
● Supports AWS, GCP, Azure
● Custom checks written in Python or YAML
● GitHub Action available
● pre-commit hook available
● Output as CLI, JSON or JUnit XML
Further reading
● https://www.checkov.io/3.Custom%20Policies/Custom%20Policies%20Overvi
ew.html
● https://aws.amazon.com/blogs/mt/introducing-aws-cloudformation-guard-2-0/
● https://aws.amazon.com/blogs/infrastructure-and-automation/use-git-pre-
commit-hooks-avoid-aws-cloudformation-errors/
● https://github.com/antonbabenko/pre-commit-terraform
Keep shifting left!
globaldatanet globaldatanet.com hello@globaldatanet.com

More Related Content

PDF
Securing your AWS Deployments with Spinnaker and Armory Enterprise
PDF
Serverless security - how to protect what you don't see?
PDF
Terrascan - Cloud Native Security Tool
PDF
Pragmatic Cloud Security Automation
PDF
Battle in the Clouds - Attacker vs Defender on AWS
PDF
AWS DevOps Event - Innovating with DevOps on AWS
PPTX
The Future of Enterprise Applications is Serverless
PDF
Using Splunk/ELK for auditing AWS/GCP/Azure security posture
Securing your AWS Deployments with Spinnaker and Armory Enterprise
Serverless security - how to protect what you don't see?
Terrascan - Cloud Native Security Tool
Pragmatic Cloud Security Automation
Battle in the Clouds - Attacker vs Defender on AWS
AWS DevOps Event - Innovating with DevOps on AWS
The Future of Enterprise Applications is Serverless
Using Splunk/ELK for auditing AWS/GCP/Azure security posture

What's hot (16)

PPTX
Serverless beyond AWS Lambda
PPTX
Of CORS thats a thing how CORS in the cloud still kills security
PPTX
Native cloud security monitoring
PPTX
Serverless Summit 21 - Resilient serverless architecture on AWS
PDF
20170831 - Greg Palmier: Terraform & AWS at Tempus
PDF
Spring Cloud Netflix OSS
PDF
AWS Security
PPTX
stackArmor Security MicroSummit - AWS Security with Splunk
PDF
SRE & Kubernetes
PPTX
How to build the Cloud Native applications the way you want – not the way the...
PDF
Monitoring Your AWS EKS Environment with Datadog
PDF
Enforce compliance policy with model-driven automation
PDF
淺談WAF在AWS的架構
PPTX
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
ODP
Hybris install telco accelerators on aws-ec2
PDF
Observability Enhancements in Steeltoe
Serverless beyond AWS Lambda
Of CORS thats a thing how CORS in the cloud still kills security
Native cloud security monitoring
Serverless Summit 21 - Resilient serverless architecture on AWS
20170831 - Greg Palmier: Terraform & AWS at Tempus
Spring Cloud Netflix OSS
AWS Security
stackArmor Security MicroSummit - AWS Security with Splunk
SRE & Kubernetes
How to build the Cloud Native applications the way you want – not the way the...
Monitoring Your AWS EKS Environment with Datadog
Enforce compliance policy with model-driven automation
淺談WAF在AWS的架構
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
Hybris install telco accelerators on aws-ec2
Observability Enhancements in Steeltoe
Ad

Similar to Shift Left - How to improve your security with checkov before it’s going to production (8)

PDF
Shift Left. Wait, what? No, Shift Right!!!
DOCX
Shift Left Save Resources DevSecOps and the CICD Pipeline
PDF
The left is not wrong, just not right; It's time to shift right!
PDF
Cncf checkov and bridgecrew
PPTX
Shifting left – embedding security into the devops pipeline by Mike d. Kail
PDF
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
PDF
Ops Happen: Improve Security Without Getting in the Way
PDF
AWS Infrastructure Pipeline with Terraform and Pre-commit Check
Shift Left. Wait, what? No, Shift Right!!!
Shift Left Save Resources DevSecOps and the CICD Pipeline
The left is not wrong, just not right; It's time to shift right!
Cncf checkov and bridgecrew
Shifting left – embedding security into the devops pipeline by Mike d. Kail
Cisco_eBook_ShiftLeftSecurity_2022_06_07a.pdf
Ops Happen: Improve Security Without Getting in the Way
AWS Infrastructure Pipeline with Terraform and Pre-commit Check
Ad

Recently uploaded (20)

PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PPTX
Reimagine Home Health with the Power of Agentic AI​
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
PPTX
L1 - Introduction to python Backend.pptx
PDF
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
Digital Strategies for Manufacturing Companies
PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
medical staffing services at VALiNTRY
PDF
System and Network Administration Chapter 2
PPTX
Operating system designcfffgfgggggggvggggggggg
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PDF
wealthsignaloriginal-com-DS-text-... (1).pdf
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Nekopoi APK 2025 free lastest update
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 41
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
Reimagine Home Health with the Power of Agentic AI​
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
Adobe Premiere Pro 2025 (v24.5.0.057) Crack free
L1 - Introduction to python Backend.pptx
T3DD25 TYPO3 Content Blocks - Deep Dive by André Kraus
Design an Analysis of Algorithms II-SECS-1021-03
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Softaken Excel to vCard Converter Software.pdf
Digital Strategies for Manufacturing Companies
Which alternative to Crystal Reports is best for small or large businesses.pdf
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
medical staffing services at VALiNTRY
System and Network Administration Chapter 2
Operating system designcfffgfgggggggvggggggggg
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
wealthsignaloriginal-com-DS-text-... (1).pdf
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Nekopoi APK 2025 free lastest update
Internet Downloader Manager (IDM) Crack 6.42 Build 41

Shift Left - How to improve your security with checkov before it’s going to production

  • 1. Anton Grübel, AWS DevOps Engineer SHIFT LEFT How to improve your security with checkov before it’s going to production
  • 2. Me, Myself & I ● AWS Enthusiast ● Python Fan ● Open Source Contributor ● Playstation Gamer ● GitHub: gruebel ● PSN: anton-mai
  • 3. About us 2017 Founded 100% AWS-focussed 20 Talents 33 AWS Certifications 1 AWS Competency 1 APN Ambassador 1 AWS Community Builder
  • 4. What is Shift Left? Shift Left is a practice intended to find and prevent defects early in the software delivery process. The idea is to improve quality by moving tasks to the left as early in the lifecycle as possible. Kirstie Magowan (bmc)
  • 7. IaC security tools ● cfn-nag ● terrascan ● KICS ● tfsec ● terraform-compliance ● AWS CloudFormation Guard ● checkov
  • 9. checkov features ● Over 1000 built-in policies ● Supports Terraform (+ plan), CFN, ARM, Docker, Kubernetes, Helm, SLS ● Supports AWS, GCP, Azure ● Custom checks written in Python or YAML ● GitHub Action available ● pre-commit hook available ● Output as CLI, JSON or JUnit XML
  • 10. Further reading ● https://www.checkov.io/3.Custom%20Policies/Custom%20Policies%20Overvi ew.html ● https://aws.amazon.com/blogs/mt/introducing-aws-cloudformation-guard-2-0/ ● https://aws.amazon.com/blogs/infrastructure-and-automation/use-git-pre- commit-hooks-avoid-aws-cloudformation-errors/ ● https://github.com/antonbabenko/pre-commit-terraform
  • 11. Keep shifting left! globaldatanet globaldatanet.com hello@globaldatanet.com

Editor's Notes

  • #4: Partnerships
  • #12: https://awesomeopensource.com/project/toniblyx/my-arsenal-of-aws-security-tools