# bridgecrewio/terragoat

TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.

Repository: https://github.com/bridgecrewio/terragoat
Canonical: https://ross.abutalabs.com/products/terragoat
Homepage: https://www.bridgecrew.io/
Language: HCL
License: Apache-2.0
License Family: permissive
Topics: terraform, aws-security, cloud-security, goat, azure-security, gcp-security, devsecops
Last push: 2025-07-13T12:11:17+00:00

## Health v2 (maintenance only)
Score: 37/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 31, release rhythm 8, longevity 100
- inputs: {"age_days": 2350, "days_push": 416, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1305, forks 5832 (observed 2026-08-28T04:04:18.654072+00:00)

## What it is
TerraGoat is Bridgecrew's 'Vulnerable by Design' Terraform repository containing intentionally misconfigured cloud infrastructure for AWS, Azure, and GCP. It serves as a training ground for practicing secure infrastructure-as-code development and testing policy-as-code scanners like Checkov.

## Use cases
- test a policy-as-code scanner against intentionally vulnerable terraform
- train devsecops engineers on common cloud misconfigurations
- demo cloud security scanning tools like checkov
- practice finding infrastructure-as-code vulnerabilities in aws azure and gcp
- set up a vulnerable terraform environment for security workshops
- evaluate inline linters and pre-commit hooks for terraform security

## When to choose
- you need a safe baseline of vulnerable Terraform code to test IaC security scanners
- you are teaching or learning DevSecOps and cloud misconfiguration prevention
- you want to demo or benchmark tools like Checkov, Bridgecrew, or other policy-as-code frameworks

## When to avoid
- you need production-ready secure Terraform modules
- you cannot risk deploying vulnerable resources into a real cloud account
- you are looking for a security scanning tool rather than vulnerable sample code

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, infrastructure-as-code, testing, developer-tools
- domain: security, cloud-computing, infrastructure-as-code, tutorials
- platform: cross-platform, cli
- tags: vulnerable-by-design, terraform, devsecops, policy-as-code, misconfiguration, aws, azure, gcp, checkov, training, devops

## Member repositories
- bridgecrewio/terragoat (main) score 37

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:18.654072+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:51:01.306298+00:00, confidence not recorded.
  - readme: https://github.com/bridgecrewio/terragoat (fetched 2026-08-28T04:04:18.654072+00:00, sha a8639a027666)
- Data as of 2026-08-30T08:39:29.467469+00:00.
