{
  "id": 11791911,
  "title": "tf-nag: offline AWS Solutions checks for Terraform plans",
  "url": "https://urgent.news/2026/10/03/tf-nag-offline-aws-solutions-checks-for-terraform-plans",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T23:12:11.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aws-builders/tf-nag-offline-aws-solutions-checks-for-terraform-plans-10ia"
  },
  "original_language": "en",
  "account": "tf-nag is an offline Python command-line interface (CLI) tool designed to audit Terraform plan or state JSON files against AWS Solutions rules. It does not require network access or any AWS credentials to operate. The rule IDs and severity levels in tf-nag are sourced from the AWS Solutions pack, which is derived from AWS Config managed rules and conformance packs. This means that each tf-nag finding can be traced back to a specific AWS-published control.\n\nUsing tf-nag allows developers to catch potential issues in their infrastructure as code (IaC) before it is deployed to production. This helps ensure that the deployed infrastructure adheres to security best practices, such as having access logs enabled, using encrypted volumes, and avoiding the use of wildcard IAM policies or outdated runtime environments.\n\nCompare to Checkov, another popular IaC scanner, tf-nag is more focused, only enforcing AWS Solutions rules on Terraform plans. While Checkov has a broader policy set and can scan multiple frameworks, tf-nag provides a more faithful representation of the AWS Config rules and is therefore more complete within that specific lineage.\n\nAn example scenario where tf-nag shines is when a team relies on Checkov for their IaC scanning but encounters issues when AWS deprecates a Lambda runtime. In this case, tf-nag can detect the outdated Lambda runtime with the AwsSolutions-L1 (ERROR) rule, ensuring that the infrastructure remains compliant with the latest AWS standards.",
  "summary": "tf-nag is an offline Python CLI that checks Terraform plan or state JSON against the tf-nag AWS Solutions rules. It does not contact AWS. Rule IDs and severity levels are derived from the upstream AWS Solutions pack: https://github.com/cdklabs/cdk-nag . cdk-nag's Rules and Packs are in turn derived from AWS Config managed rules and conformance packs, so a tf-nag finding traces back through…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}