docs(iac): add IaC getting started in Cloud/App (#9152)

This commit is contained in:
Andoni Alonso
2025-11-05 09:20:18 +01:00
committed by GitHub
parent 02489a5eef
commit 5b20fd1b3b
6 changed files with 51 additions and 12 deletions
@@ -1,6 +1,7 @@
---
title: "Getting Started with the IaC Provider"
---
import { VersionBadge } from "/snippets/version-badge.mdx"
Prowler's Infrastructure as Code (IaC) provider enables scanning of local or remote infrastructure code for security and compliance issues using [Trivy](https://trivy.dev/). This provider supports a wide range of IaC frameworks, allowing assessment of code before deployment.
@@ -22,8 +23,46 @@ The IaC provider leverages [Trivy](https://trivy.dev/latest/docs/scanner/vulnera
- Mutelist logic ([filtering](https://trivy.dev/latest/docs/configuration/filtering/)) is handled by Trivy, not Prowler.
- Results are output in the same formats as other Prowler providers (CSV, JSON, HTML, etc.).
## Prowler App
<VersionBadge version="5.14.0" />
### Step 1: Access Prowler Cloud/App
1. Navigate to [Prowler Cloud](https://cloud.prowler.com/) or launch [Prowler App](/user-guide/tutorials/prowler-app)
2. Go to "Configuration" > "Cloud Providers"
![Cloud Providers Page](/images/prowler-app/cloud-providers-page.png)
3. Click "Add Cloud Provider"
![Add a Cloud Provider](/images/prowler-app/add-cloud-provider.png)
4. Select "Infrastructure as Code"
![Select Infrastructure as Code](/images/providers/select-iac.png)
5. Add the Repository URL and an optional alias, then click "Next"
![Add IaC Repository URL](/images/providers/add-iac-repo.png)
### Step 2: Enter Authentication Details
6. Optionally provide the [authentication](/user-guide/providers/iac/authentication) details for private repositories, then click "Next"
![IaC Authentication](/images/providers/iac-authentication.png)
### Step 3: Verify Connection & Start Scan
7. Review the provider configuration and click "Launch scan" to initiate the scan
![Verify Connection & Start Scan](/images/providers/iac-verify-connection.png)
## Prowler CLI
<VersionBadge version="5.8.0" />
### Usage
Use the `iac` argument to run Prowler with the IaC provider. Specify the directory or repository to scan, frameworks to include, and paths to exclude.