Conftest is a free utility for checking structured configuration data against policies, particularly in continuous integration environments. It uses the Open Policy Agent Rego language, evaluating deny, violation, and warning rules within namespaces. Inputs can be supplied as one or more files, directories, or standard input. Supported formats include Kubernetes-style YAML, JSON, HCL and HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, and XML. Results can be written as plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps, or SARIF output; its GitHub output can annotate findings in workflows. The `conftest verify` command runs policy unit tests. Policies can be retrieved from HTTPS URLs, Git repositories, and OCI registries, and pushed to compatible OCI registries. Plugins extend the command-line tool, and pre-commit hooks support policy tasks such as testing, documenting, pulling, and formatting. The project documents integrations with CircleCI, GitHub Actions, and Tekton. Conftest is built on Open Policy Agent and runs on Linux, macOS, and Windows. It is available under the Apache License 2.0.
Who it is for
Conftest suits developers and teams who want policy checks for structured configuration in CI workflows. It supports Kubernetes, Terraform-related data, and other listed formats.
What is good
- Free under the Apache License 2.0.
- Accepts numerous configuration formats and input methods.
- Offers CI-focused output formats, including JUnit and SARIF.
- Policies and plugins can be retrieved from multiple sources.
- Pre-commit hooks cover several policy tasks.
What to know first
- The deprecated instrumenta/conftest image should not be used.
- Questions and discussions are directed to the OPA Slack channel.
Freedom251 review
Conftest: the full review
Conftest provides policy-based configuration checks with a broad set of inputs and CI outputs. Teams can use its integrations, plugins, and pre-commit hooks to fit those checks into existing workflows.
Overview
Conftest is a command-line utility for checking structured configuration against policies written in Open Policy Agent’s Rego language. It is best suited to teams that want configuration checks in CI and are prepared to work with policy code. Its breadth of input formats and automation outputs makes it adaptable, but it is a policy-testing tool rather than a turnkey visual management service.
It covers Kubernetes configurations, Tekton pipelines, Terraform code, Serverless configurations, and other structured data. Teams can test a single file, a directory, multiple files, or standard input, which makes it possible to place checks at different points in a configuration workflow.
Key features
Conftest evaluates deny, violation, and warn rules and supports namespaces. The conftest verify command runs policy unit tests, so teams can validate the rules as well as the configurations those rules govern. That is useful when policy changes need their own checks, though the approach assumes users can write and maintain Rego.
Supported inputs include YAML, JSON, HCL and HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, XML, and other formats. Results can be emitted as plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps, or SARIF. The GitHub outputter can annotate test results in workflows, and documented integrations include CircleCI, GitHub Actions, and Tekton Pipelines. This range suits teams working across different CI environments; users still need to configure their chosen workflow around the CLI.
Policies can be pulled from HTTPS URLs, Git repositories, and OCI registries, and pushed to compatible OCI registries. Plugins extend the CLI and can be downloaded from OCI registries, local files, Git, HTTP or HTTPS, Mercurial, Amazon S3, and Google Cloud Storage. Pre-commit hooks cover testing, verifying, documenting, pulling, and formatting policies, bringing checks closer to the point where changes are made.
Release assets, checksum files, and container images carry GitHub artifact attestations with SLSA provenance signed through Sigstore. Conftest can be installed through Homebrew, Scoop, Mise, Docker, or from source. The older instrumenta/conftest container image is deprecated; users should use openpolicyagent/conftest.
Pricing
Conftest is open source under the Apache License 2.0. The Open-source Conftest plan costs 0.00 USD per free. There are no paid tiers or seat-based plan distinctions to weigh in the stated pricing model, which makes it a straightforward option for teams that want policy checks without a software subscription.
Platforms
Conftest supports Linux, macOS, and Windows. Its installation routes include package managers, Docker, and source builds, giving teams several ways to fit deployment to their environment.
Who it's for
Conftest is a strong fit for infrastructure and platform teams that need repeatable policy checks for Terraform, Kubernetes, or other structured configuration in CI. It is also relevant to teams that want policy unit tests, pre-commit checks, and CI-friendly result formats in the same utility. It is a weaker fit for users seeking a graphical policy editor or a system that removes the need to author policy rules.
Pros and cons
- Broad format coverage: It handles common infrastructure configuration formats as well as JSONnet, TOML, and XML, useful for teams with mixed inputs.
- Fits varied CI workflows: GitHub annotations and outputs such as JUnit, Azure DevOps, and SARIF let results flow into several automation environments.
- Policy lifecycle support: Unit testing, pre-commit hooks, policy sharing, and plugins extend its use beyond a single configuration check.
- Requires policy-code ownership: Teams must be ready to write and maintain Rego rules; the utility does not replace that work with a visual policy-management workflow.
- Container image migration matters: Users relying on the deprecated instrumenta image need to switch to openpolicyagent/conftest.
Alternatives
Terraform is worth considering when the priority is Terraform’s broader freemium offering: its free plan includes 500 managed resources, one concurrent remote run, and one concurrent agent run. Choose Conftest instead when the central need is Rego-based policy checks across varied configuration formats.
Google Cloud Terraform Policy Validation is a more focused option for teams seeking a free, client-side Terraform policy validation tool in beta. Conftest supports a wider range of configuration inputs and CI output formats.
Open Policy Agent is the natural alternative for teams looking for the open-source policy engine itself; Conftest is built on top of OPA and offers a utility specifically for testing structured configuration.
AWS CloudFormation may suit teams focused on provisioning through that service, which is free to use while underlying AWS resources are billed at their own rates. cfn-lint, Cloud Custodian, KICS, and Kyverno are other free alternatives to consider.
For more options, browse Infrastructure Policy as Code Tools, Infrastructure Testing Tools, and Infrastructure as Code Security Software.
Verdict
Choose Conftest if your team wants free, CI-oriented policy checks across infrastructure and other structured configuration, and has the Rego skills to maintain its rules. Its combination of broad input support, automated output formats, and policy-testing tools is compelling for that use. Look elsewhere if you need a visual policy-management experience or want to avoid owning policy code. Questions and discussion are directed to the Open Policy Agent Slack channel #opa-conftest.
Conftest plans and pricing
All plansCompared on infrastructure testing tools
- Free plan
- Yes
- Terraform analysis
- Yes
- Kubernetes analysis
- Yes
- Custom policies
- Yes
- Pull request scanning
- Yes


