> TheAuditor / blog
• cloud, iac

Your Infrastructure Config Is Code Too

TheAuditor analyzes your infrastructure configuration through the same data-flow graph as your application code, across twelve infrastructure-as-code substrates, so misconfigurations surface as connected data-flow exits instead of isolated file-lint results that miss the context.

Most tools treat infrastructure configuration as a second kind of thing. Your application code goes through the real analysis; your Terraform, your Kubernetes manifests, your Dockerfiles get a separate linter that reads one file at a time and reports what looks wrong in isolation. That split is why a public bucket and the application path that writes untrusted data into it show up as two unrelated findings, if they show up at all.

We do not run infrastructure config through a side channel. It goes through the same data-flow graph as the code around it.

One graph, application and infrastructure together

TheAuditor recognizes twelve infrastructure-as-code substrates and reads each one as a first-class input, not as text to spell-check:

  • Terraform and CloudFormation
  • Helm, Kubernetes manifests, and Kustomize
  • Dockerfiles and Compose
  • nginx and Traefik
  • Pulumi, AWS CDK, and CDKTF

Because these feed the same model as your application code, a value that starts in a request handler and ends in an infrastructure resource comes back as one continuous picture, not two scans you have to reconcile by hand.

Misconfigurations as connected exits, not isolated rules

A file-lint rule can tell you a resource is public. It cannot tell you whether anything reaches it, because it never sees the rest of the system. In the shared graph, an infrastructure misconfiguration is modeled as an exit: a place where risk leaves the system, connected to whatever flows toward it.

The categories that surface this way are the ones that actually cause incidents: public exposure of a resource that should be private, wildcard permissions in an IAM policy, resources left unencrypted, and secrets hardcoded into config. Seen as connected exits, these stop being a wall of context-free warnings and start being risk you can rank, because the tool can show what reaches each one.

Honest scope note about cloud coverage

The cloud provider vocabulary spans AWS, Azure, and GCP, and we will be plain about the shape of it: AWS coverage is the most complete today, with Azure and GCP filling in behind it. Where a provider or a resource is not yet modeled, the engine reports the gap rather than returning a confident all-clear it cannot back. Infrastructure coverage grows the same way the rest of the engine does, by addition, against public standards, with the remaining gaps named instead of hidden.

Where this sits

Following data from application code into the infrastructure around it is the same connective work that makes cross-language findings possible, held to an independent yardstick at BenchProctor. TheAuditor is the ground-truth layer for Code Reality Labs, and it ships when its hardening checks pass. Subscribe on the main site for launch news.

Was this useful?