DEV Community

Cover image for Level-Up Your AWS CDK Game: Shift Left Security Unveiled!

Level-Up Your AWS CDK Game: Shift Left Security Unveiled!

Jatin Mehrotra on March 13, 2024

Infrastructure as Code (IaC) benefits are known to everyone and one of the major benefits is to offer rapid infrastructure deployment as a major b...
Collapse
 
airmonitor profile image
Tomasz Szuster

Hey,

Thx for your article, I'm wondering what is your opinion about cdk-nag?

github.com/cdklabs/cdk-nag

Checkmarx product and cdk-nag are doing the same I think,

Collapse
 
jatinmehrotra profile image
Jatin Mehrotra

Hello @airmonitor

Thank you for reading my blog and your views. Yes they are doing similar thing, I haven't used cdk-nag. Will give it a try.

But to answer your question, syntactically I prefer the checkmark Plugin more as it is easy to use and operate, plus the way it generates reports is far better than cdk-nag IMO.

1 difference which I could see is:

  • how to suppress errors which again is operationally far easier and better in the checkmarks plugin.

I am giving these views on the basis of this blog by AWS: aws.amazon.com/blogs/devops/manage...

Collapse
 
felixbrm profile image
Felix Berman

@jatinmehrotra An awesome deep dive into the KICS CDK validation plugin! Also, thank you for pointing out the issue with code example in my blog - I'll update it shortly.

Collapse
 
jatinmehrotra profile image
Jatin Mehrotra

@felixbrm Thank you for introducing this amazing plugin in the first place. In this deep dive, I was able to test many breaking edge cases which I will be open in KICS GitHub soon.

I am glad my blog was helpful.