Enforce custom rules in Datadog IaC Security scanning
Blog post from Datadog
Datadog IaC Security custom rules allow security and platform teams to supplement default misconfiguration checks with organization-specific infrastructure policies, such as required tags, approved instance types, naming standards, network boundaries, and compliance requirements. Written in Rego and supported across Ansible, AWS CloudFormation, Dockerfiles, Kubernetes, Terraform, and GitHub Actions, these policies run alongside default rules in repository scans and can be configured by repository, path, severity, or individual rule. Users with the required permissions can create rules from scratch, clone existing policies, or use an AI-assisted natural-language rule creator that generates Rego code and sample configurations. Rules can be tested in the editor, saved as drafts, published when ready, and tracked through version history with comparison and rollback capabilities. Once published, violations appear in existing Datadog workflows, including pull request comments, IDE extensions, the findings explorer, PR Gates, and automated remediation pipelines, enabling teams to enforce internal standards before deployment without creating separate review processes.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Kubernetes | 1 | 956 | 75 | 30 | -73% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.