Checkov In A venv Of Its Own
Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
checkov
The Prisma Cloud (Bridgecrew) CLI (checkov) on EL 10, pinned to a version, in a virtual
environment of its own with a link in the PATH. Original role for EL 10,
live-tested with podman on Rocky Linux 10.
There is no package; the documented install is pip. EL 10 carries no
checkov, and pip install into the system Python ties the CLI's
dependencies to whatever the OS ships. This role puts the CLI in
/opt/checkov, a venv apart from the system Python: an OS update
cannot break it, and it cannot break the OS. The live test asserts
import checkov fails in /usr/bin/python3.
Pinned, and checked for consistency. checkov_version is what gets
installed; the live test runs pip check inside the venv and expects no
broken requirements.
pip verifies nothing beyond TLS. The index is PyPI over HTTPS; there is
no signature to check. For a byte-for-byte pin, give
checkov_pip_extra_args a requirements file with hashes and
--require-hashes, or a private index.
Proven to run. The live test calls checkov -d /tmp/ckv --framework terraform --quiet --compact --skip-download and expects
"Failed checks:" - the whole tree loaded and the scanner did its work.
Offline by request. Checkov fetches external check bundles and
reports to a platform unless told not to; the live test passes
--skip-download and scans a one-resource module (an S3 bucket with
nothing configured) with the built-in checks, expecting a "Failed checks:"
summary: the parser, the graph and the check runner all ran, with no
network. Checkov is a large Python tree (dozens of dependencies); the
venv keeps it off the system Python, which the live test asserts.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-conftest
conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.
ansible-consul-cli
consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
ansible-gh-cli
gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.
ansible-infracost
infracost on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 Infracost publishes, re-checked by the live test, which then runs a breakdown with no API key and expects it to stop there. The role exports INFRACOST_SKIP_UPDATE_CHECK=true for login shells and the live test reads it back. Original role, live-tested on Rocky Linux 10.
ansible-nomad-cli
nomad on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs nomad status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.
ansible-opa
opa on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 OPA publishes, and re-checked with sha256sum -c by the live test, which then evaluates a one-rule Rego v1 policy against a one-line input with opa eval and expects the denial. The binary only; no opa server. Original role, live-tested on Rocky Linux 10.