Cloud (IaC) Security Plugin for IntellIJ IDEA

Welcome to the IntelliJ IDEA Cloud (IaC) Security (source code) plugin documentation site. This plugin provides capabilities to detect Docker and Kubernetes security misconfiguration. The IntelliJ IDEA plugin is not limited to security misconfiguration. It also covers other maintainability problems, including trivy and most of the hadolint rules written in pure Kotlin, utilizing JetBrains IDE features.

Working on that plugin started almost one year ago, and with constant improvement, I added many rules to provide more IDEA security features. If you’re interested in my journey into security plugin development, you could read my story about IntelliJ Plugin: Building Docker Security Analysis Tools.

On that page, you can find information about plugin inspections and Docker and Kubernetes (Security) Best Practices: