Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
Describe the issue
We run the checkov in both image (ghcr.io/antonbabenko/pre-commit-terraform:latest) and local (MacOS), but got the two different result unfortunately.
We have the AWS EIP attached to the NAT gateway(CKV2_AWS_19) and not setting the default VPC's security group to restrict all traffic(CKV2_AWS_12). The test we run in the image showed these two alerts, whereas the local test showed that all of the checks were passed. The Checkov versions are both the same, which are 3.2.90, in both environments.
The way we test with docker image is to mount the local directory into image by the following command:
docker run -it --entrypoint "" -v $PWD:/app [image_hash] bash
As for the local setup, we install Checkov through HomeBrew.
Describe the issue We run the checkov in both image (
ghcr.io/antonbabenko/pre-commit-terraform:latest
) and local (MacOS), but got the two different result unfortunately.We have the AWS EIP attached to the NAT gateway(
CKV2_AWS_19
) and not setting the default VPC's security group to restrict all traffic(CKV2_AWS_12
). The test we run in the image showed these two alerts, whereas the local test showed that all of the checks were passed. The Checkov versions are both the same, which are 3.2.90, in both environments.The way we test with docker image is to mount the local directory into image by the following command:
As for the local setup, we install Checkov through HomeBrew.
Examples The Terraform code for
CKV2_AWS_19
The result generated in local:![image](https://github.com/bridgecrewio/checkov/assets/39018591/27a0d734-4b07-4402-b82b-66ddb98d56a1)
The result generated in docker container:![截圖 2024-05-10 18 00 26](https://github.com/bridgecrewio/checkov/assets/39018591/3397028b-216e-4a7e-a98d-6c2c3d49b570)
Additionally, we run the tests without any customization, so there is no
.checkov.yaml
example file.Desktop (please complete the following information):