A comprehensive collection of security-hardened Infrastructure as Code (IaC) templates following industry best practices. This repository provides production-ready modules for Terraform, CloudFormation, and Ansible that implement security controls from the ground up.
- Terraform Security Modules: Hardened AWS, Azure, and GCP resources
- CloudFormation Templates: Security-first AWS infrastructure patterns
- Ansible Playbooks: System hardening and compliance automation
- Policy-as-Code: Validation rules and security policies
- Compliance Frameworks: CIS, NIST, and SOC 2 alignment
- Zero Trust Architecture: Network segmentation and access controls
secure-iac-templates/
├── terraform/
│ ├── modules/
│ │ ├── aws-secure-vpc/
│ │ ├── azure-secure-network/
│ │ ├── gcp-secure-project/
│ │ └── kubernetes-security/
│ ├── policies/
│ │ ├── security-groups.rego
│ │ ├── s3-bucket-policies.rego
│ │ └── iam-policies.rego
│ └── examples/
├── cloudformation/
│ ├── security-templates/
│ │ ├── secure-vpc.yaml
│ │ ├── waf-protection.yaml
│ │ └── logging-compliance.yaml
│ └── nested-stacks/
├── ansible/
│ ├── playbooks/
│ │ ├── linux-hardening.yml
│ │ ├── windows-hardening.yml
│ │ └── docker-security.yml
│ ├── roles/
│ │ ├── cis-hardening/
│ │ ├── security-baseline/
│ │ └── compliance-audit/
│ └── inventories/
├── policies/
│ ├── opa/
│ ├── sentinel/
│ └── conftest/
├── docs/
│ ├── terraform-security-guide.md
│ ├── cloudformation-best-practices.md
│ └── ansible-hardening-guide.md
└── scripts/
├── security-scan.sh
├── policy-validate.sh
└── compliance-check.sh
module "secure_vpc" {
source = "./terraform/modules/aws-secure-vpc"
vpc_cidr = "10.0.0.0/16"
enable_flow_logs = true
enable_vpc_endpoints = true
encryption_at_rest = true
compliance_framework = "SOC2"
}aws cloudformation create-stack \
--stack-name secure-infrastructure \
--template-body file://cloudformation/security-templates/secure-vpc.yaml \
--parameters ParameterKey=Environment,ParameterValue=productionansible-playbook -i inventories/production \
playbooks/linux-hardening.yml \
--extra-vars "compliance_level=high"- VPC with private subnets and NAT gateways
- Security groups with least privilege access
- Network ACLs for additional layer protection
- VPC Flow Logs for monitoring
- Encryption at rest and in transit
- KMS key management and rotation
- Secure parameter storage
- Database encryption
- IAM roles with minimal permissions
- Multi-factor authentication enforcement
- Service account security
- Resource-based policies
- CloudTrail logging
- Security hub integration
- Compliance dashboard
- Automated security scanning
- CIS Benchmarks: Center for Internet Security controls
- NIST CSF: Cybersecurity Framework alignment
- SOC 2: Service Organization Control requirements
- PCI DSS: Payment Card Industry standards
- ISO 27001: Information security management
All templates include policy-as-code validation using:
- Open Policy Agent (OPA): Rego policy language
- HashiCorp Sentinel: Policy enforcement
- Conftest: Kubernetes policy testing
- Review Security Settings: Understand each template's security implications
- Customize for Environment: Adapt templates to your specific requirements
- Test in Staging: Validate templates in non-production environments
- Monitor Compliance: Use included monitoring tools
- Regular Updates: Keep templates updated with latest security practices
- Fork the repository
- Create a feature branch (
git checkout -b feature/security-enhancement) - Commit changes (
git commit -am 'Add new security control') - Push to branch (
git push origin feature/security-enhancement) - Create Pull Request
Please report security vulnerabilities to: security@example.com
This project is licensed under the MIT License - see the LICENSE file for details.
- Documentation: docs/
- Issues: GitHub Issues
- Security: Security Policy
Disclaimer: These templates are provided as-is. Always review and test in your environment before production deployment.