Chef InSpec
chef.io
Chef InSpec is a compliance-as-code framework for auditing and testing the state and security of infrastructure. It is used to run CIS benchmark-based audits and scan cloud accounts, containers, and Kubernetes clusters for misconfigurations, and it can be authored, tested, and run from within Chef Workstation. InSpec is also offered as a supported skill inside the broader Chef 360 Platform's Enterprise and Enterprise Plus plans, where it powers continuous compliance and cloud security scanning use cases.
What it's for
Features 7
- Authoring, testing, and running InSpec code via Chef Workstation
- CIS benchmark-based audit content
- Cloud account scanning for security risks and misconfigurations
- Compliance-as-code framework for auditing and testing infrastructure state and security
- Included as a supported orchestration skill in Chef 360 Enterprise and Enterprise Plus plans
- Kubernetes cluster and container scanning
- Usable in air-gapped AWS Cloud environments
At a glance
Resources
Pricing
No standalone price is listed for Chef InSpec. It appears as an included 'supported skill' (alongside Infra) within the Chef 360 Platform's Enterprise ($189 per node/year) and Enterprise Plus (custom quote) plans; the Business plan ($59 per node/year) lists only Shell, Restart, Gohai and Courier Runner skills without InSpec.