Cloud Baseline Checker
Paste Terraform for AWS or Google Cloud, or the JSON from terraform show -json. The Cloud Baseline Checker tests each resource against 31 security baseline rules (public buckets, internet-open ports, admin IAM, IMDSv1, unrotated keys, secrets in code) and gives the fix plus the AWS Config rule or GCP log filter that catches it in production.
Your Terraform never leaves this tab. Plan files can hold secrets, so nothing is uploaded.
How the baseline check works
The page reads each resource and data block from HCL, or each resource in the planned values of a plan JSON, including resources inside modules. Every rule applies to specific resource types and checks the settings that cause real incidents in AWS and Google Cloud. Each finding names the resource, the line or module address, the exact setting at fault, why it matters, the fix in Terraform, and the managed rule or log query that detects the same problem in a live account.
- Plan JSON is the stronger input. Run
terraform plan -out plan.outthenterraform show -json plan.out. Module contents and resolved values appear there, where a .tf file only shows what is typed literally. - Some rules need a human call, such as a public Cloud Run service or a wildcard bucket policy. The finding says what to confirm.
- Detection lines name AWS Config managed rules and GCP Security Command Center findings or Cloud Logging filters, so a security operations team can alert when the same setting drifts in production.
All 31 rules
Cloud baseline FAQ
Should I paste a .tf file or a plan JSON?
A plan JSON is more complete. Run terraform plan -out plan.out, then terraform show -json plan.out, and paste the output. It has module contents and resolved values, where .tf files only show what is written literally. Paste .tf files for a quick check during review.
Does this replace Checkov, tfsec or Trivy?
No. Those run hundreds of policies in CI with a real HCL parser. This page checks 31 high-impact settings in the browser, explains each one, and gives the matching AWS Config rule or GCP log filter, so it suits code review, learning and a quick look at a file someone sent you.
Is my Terraform sent anywhere?
No. The parser and rules run in JavaScript on the page. Plan files can hold secrets and resource names, so nothing is uploaded.
Why is a rule marked for confirmation?
Some settings are right in one design and wrong in another. A Cloud Run service open to allUsers is correct for a public API with its own auth, and a bucket policy with a wildcard principal can serve a public website. The finding says what to confirm.
Rules reflect AWS and Google Cloud defaults and provider attribute names as of October 2026. Sample code on this page is fake.