October 25, 2021
2
min

Simulate Terraform Changes and their Impact in Terraform Cloud with Stream Security Run Tasks Integration

HashiCorp Terraform Cloud run tasks feature was announced earlier this year and is now available for integration with Stream Security's continuous simulation platform. Learn more about our partnership in this article
Amit Hacohen
No items found.

TL;DR

The new HashiCorp Terraform Cloud run tasks feature was announced earlier this year and is now available for integration with Stream Security's continuous simulation platform. It was very exciting for us when the team at HashicCorp approached us to partner with them on this, as our customers frequently asked us if we support a native integration with Terraform Cloud. Now we can answer them: Yes!

The run tasks feature enables your organization to integrate third-party tools within a Terraform run, specifically between the plan and apply stages of the Terraform Cloud workflow. A run task works by sending run-related information to Stream Security. Stream then uses a real-time representation of your cloud environment and will simulate proposed changes as if your Terraform code was already deployed.

With this new integration, on each workflow run you will be able to understand how your Terraform code is going to impact the destined environment before applying the code and it will reduce the chance for mistakes and misconfigurations from hitting your production environment.

A good example is a change to security group rules or an IAM policy statement which is attached to a role that is assumed by multiple resources. A mistake in this code can cause dependent resources to lose reachability or gain unintendedly access. Using Stream Security's Simulation will enable you to immediately understand if the proposed change is going to achieve the original requirement and also make sure that misconfigurations will not be applied to a live environment.

All you need to start simulating Terraform changes directly from Terraform Cloud is Stream Security integrated into your Terraform Cloud workflow with the run tasks feature. If you haven’t created your Stream Security environment yet click here to sign up.

The Terraform Cloud run tasks feature has been turned on for all existing HashiCorp Terraform Cloud Business tier customers. If you are interested in the run tasks feature and are not yet a Business tier customer of Terraform Cloud, make sure to sign up here for access.

About Stream Security

Stream is the AI-native platform built to fight AI-enabled attacks. It autonomously prevents, detects, hunts, and remediates exposures and threats across production at machine speed - driving risk toward zero. It replaces the fragmented stack of scanners, runtime agents, exposure tools and playbooks with one live model of production.Defending Production needs a new approach: Stream is the only Autonomous Production Defense Platform that works across your entire production estate. It runs on a patented CloudTwin®, a high-fidelity security data harmonization layer that models Cloud, SaaS, identity, runtime, AI, network, perimeter, on-prem, security controls, and the behavior running on top of them into one live model of production: real-time, fully correlated, continuously updating. Not a snapshot. And it does not stop at boundaries - the boundaries that fragment every other tool are the same boundaries an attacker moves across. Inside CloudTwin they are one system.

Amit Hacohen

We wouldn’t believe it either.

Get a demo