__ __ __ ________ __ / // /__ _____/ /__/ ___/ _ \/ / / _ / _ `/ __/ '_/ (_ / // / /__ /_//_/\_,_/\__/_/\_\\___/____/____/ PRE-CON Track 0
Building Secure Infrastructure: What developers need to know about IAC
This workshop will focus on teaching developers how to build secure infrastructure with Terraform by utilizing free and open-source tools. We'll cover the common uses of Terraform and how a malicious actor could abuse Terraform and even bypass security controls to execute unapproved code. We’ll discuss ways development teams can harden their Terraform or other IAC pipelines to ensure that infrastructure is secure.
The talk will focus on research done on Terraform implementations and ways to harden deployments. The talk will cover how Terraform works, how common Terraform security controls are applied, and multiple ways to bypass them and gain further access to environments.