Conftest
- Android app
- Not listed
- Free plan
- Yes
- Runs on
- Linux, Mac, Windows

Summary
Conftest is a free utility for testing structured configuration data, designed especially for CI environments. It uses the Open Policy Agent Rego language to express policies, then evaluates deny, violation and warning rules within namespaces. Configuration can be checked from a file, directory, multiple files or standard input. Supported formats include Kubernetes-style YAML, JSON, HCL and HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML and XML. Results can be written as plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps or SARIF output, and its GitHub formatter can annotate findings in workflows. The `conftest verify` command runs policy unit tests. Policies can be retrieved from HTTPS URLs, Git repositories and OCI registries, and sent to compatible OCI registries. Plugins extend the CLI and can be obtained through multiple sources, including OCI, Git, HTTP/HTTPS and cloud storage. Pre-commit hooks support policy testing, verification, documentation, pulling and formatting. Conftest documents integrations with CircleCI, GitHub Actions and Tekton, and is available for Linux, macOS and Windows.
Who it is for
Conftest suits teams that want to check infrastructure or other structured configuration in CI workflows. Its Rego policies and varied output formats may be useful for teams using Open Policy Agent.
What is good
- Tests Kubernetes, Terraform and other structured data.
- Accepts files, directories or standard input.
- Provides CI-oriented output formats including SARIF.
- Supports policy unit tests with `conftest verify`.
What to know first
- Uses the Open Policy Agent Rego language for policies.
- The instrumenta/conftest container image is deprecated.
Everything Xiaomi review
Conftest: the full review
Conftest provides policy-based configuration checks for CI, along with several input types, output formats and plugin sources. It is free under the Apache License 2.0 and runs on Linux, macOS and Windows.
Overview
Conftest is a command-line utility for checking configuration against policies written in Rego, the language used by Open Policy Agent. It suits teams that want policy checks inside CI and are comfortable working with policy code. Its breadth of input and CI output options is a strong fit for varied infrastructure workflows, though it is not a turnkey visual policy-management service.
Key features
Conftest checks Kubernetes-style YAML, JSON, HCL and HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, XML, and other formats. Teams can pass a single file, a directory, multiple files, or standard input, making it practical to place checks at different points in a configuration workflow. It evaluates deny, violation, and warn rules and supports namespaces, while conftest verify runs policy unit tests. That combination lets teams validate both their configurations and the policies governing them.
For automation, output can be plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps, or SARIF. The GitHub outputter can annotate results in workflows; documented integrations also cover CircleCI and Tekton Pipelines. This range helps fit results into existing CI systems, but users still need to author and maintain the Rego policies.
Policies can be pulled from HTTPS URLs, Git repositories, and OCI registries, and pushed to compatible OCI registries. Plugins extend the CLI and can be downloaded through OCI, local files, Git, HTTP or HTTPS, Mercurial, Amazon S3, or Google Cloud Storage. Pre-commit hooks cover testing, verifying, documenting, pulling, and formatting policies. These options support shared policy workflows, although they add moving parts for teams that only need a small set of local checks.
Conftest releases, checksums, and container images carry GitHub artifact attestations with SLSA provenance signed through Sigstore. It can be installed with Homebrew, Scoop, Mise, Docker, or from source. The old instrumenta/conftest container image is deprecated; deployments using a container should use openpolicyagent/conftest instead.
Pricing
Open-source Conftest costs 0.00 USD per free under the Apache License 2.0. The free plan includes the policy-checking utility; no paid plan, seat cap, or usage quota is part of this offering. It is a compelling option when a team can operate its own policy workflow, but the project directs questions and discussions to the Open Policy Agent Slack #opa-conftest channel rather than offering a paid support tier.
Platforms
Conftest runs on Linux, macOS, and Windows. The choice of Homebrew, Scoop, Mise, Docker, or source installation gives teams several ways to match installation to their environment.
Who it's for
Conftest is best for infrastructure and platform teams that already use OPA or are prepared to write Rego policies, and want configuration checks in CI. Its support for Kubernetes, Terraform, Tekton, Serverless, and other structured data suits teams governing more than one configuration type. Readers looking for a point-and-click interface or policy checks without writing rules should look elsewhere.
Pros and cons
- Pros: Broad input coverage. YAML, JSON, HCL/HCL2, Dockerfiles, JSONnet, TOML, and XML support makes one tool useful across varied configuration sources.
- Pros: CI-friendly reporting. GitHub annotations and formats such as JUnit, Azure DevOps, and SARIF help deliver findings where teams work.
- Pros: Policy workflow support. Verification, pre-commit hooks, policy sharing, and extensible plugins cover more than just running a check.
- Cons: Rego is central to the workflow. Teams that do not want to write and maintain policy code may find Conftest a poor fit.
- Cons: Community-oriented support. Questions go to the OPA Slack channel, which may not suit organizations needing formal vendor support.
Alternatives
For AWS-focused infrastructure provisioning, choose AWS CloudFormation when its AWS service model is a better fit; CloudFormation itself is free, while underlying AWS resources are billed at their own rates. Test Kitchen is another free, Apache-licensed option for readers seeking a different infrastructure testing tool. For CloudFormation template linting specifically, cfn-lint is a free alternative.
Chef InSpec offers a free plan limited to non-production workloads and personal, non-commercial use, plus a 30-day trial; consider it when those terms and its approach better match the intended use. Cinc Auditor is a free distribution of Chef InSpec, with no formal warranties or support. OpenSCAP is a free open-source option for readers comparing infrastructure security tools. TFLint is a free command-line Terraform linter, while KICS is a free open-source infrastructure policy-as-code project.
Browse Infrastructure Testing Tools, Infrastructure as Code Security Software, and Infrastructure Policy as Code Tools for more options by category.
Verdict
Choose Conftest if your team wants free, CI-oriented configuration policy checks across multiple formats and can work in Rego. Its flexible inputs, integrations, and policy tooling are the main reasons to pick it; teams that need a visual workflow or formal support should look elsewhere.
Conftest plans and pricing
All plansCompared on infrastructure testing tools
- Free plan
- Yesconftest.dev
- Terraform analysis
- Yesconftest.dev
- Kubernetes analysis
- Yesconftest.dev
- Custom policies
- Yesconftest.dev
- Pull request scanning
- Yesconftest.dev
Facts
- Purpose
- Conftest is a utility for writing tests against structured configuration data.conftest.dev · 30 Sept 2026
- Policy language
- Conftest uses the Open Policy Agent Rego language for writing policies.conftest.dev · 30 Sept 2026
- Target users
- Conftest is designed for configuration testing in CI environments.conftest.dev · 30 Sept 2026
- Supported formats
- Supported inputs include Kubernetes-style YAML, JSON, HCL/HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, XML, and other formats listed in the documentation.conftest.dev · 30 Sept 2026
- Policy rules
- Conftest evaluates deny, violation, and warn rules and supports namespaces.conftest.dev · 30 Sept 2026
- Input methods
- Configuration can be tested from files, directories, multiple files, or standard input.conftest.dev · 30 Sept 2026
- CI outputs
- Output formats include JSON, TAP, table, JUnit, GitHub, Azure DevOps, and SARIF.conftest.dev · 30 Sept 2026
- GitHub integration
- The GitHub outputter can annotate configuration test results for GitHub workflows.conftest.dev · 30 Sept 2026
- Policy sharing
- Policies can be pulled from HTTPS URLs, Git repositories, and OCI registries, and pushed to compatible OCI registries.conftest.dev · 30 Sept 2026
- Plugin system
- Plugins can extend the Conftest CLI and can be downloaded through OCI, local files, Git, HTTP/HTTPS, Mercurial, Amazon S3, or Google Cloud Storage.conftest.dev · 30 Sept 2026
- Pre-commit
- Conftest provides pre-commit hooks for testing, verifying, documenting, pulling, and formatting policies.conftest.dev · 30 Sept 2026
- Release security
- Every release asset, checksums file, and container image is attested with GitHub artifact attestations using SLSA provenance signed through Sigstore.conftest.dev · 30 Sept 2026
- Deployment options
- Conftest can be installed with Homebrew, Scoop, Mise, Docker, or from source.conftest.dev · 30 Sept 2026
- Deprecated image
- The instrumenta/conftest container image is deprecated and the documentation directs users to openpolicyagent/conftest.conftest.dev · 30 Sept 2026
- Community support
- The project directs discussions and questions to the Open Policy Agent Slack #opa-conftest channel.github.com · 30 Sept 2026
- Configuration targets
- Conftest supports Kubernetes configurations, Tekton pipeline definitions, Terraform code, Serverless configurations and other structured data.conftest.dev · 1 Oct 2026
- Policy testing
- The `conftest verify` command executes policy unit tests and reports their results.conftest.dev · 1 Oct 2026
- Output formats
- Conftest supports plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps and SARIF output.conftest.dev · 1 Oct 2026
- Plugins
- Conftest plugins extend the CLI and can be downloaded from OCI registries, local files, Git, HTTP/HTTPS, Mercurial, Amazon S3 and Google Cloud Storage.conftest.dev · 1 Oct 2026
- CI integration
- The project documents integrations with CircleCI, GitHub Actions and Tekton Pipelines.cncf.io · 1 Oct 2026
- Support
- Questions and discussions are directed to the Open Policy Agent Slack channel `#opa-conftest`.github.com · 1 Oct 2026
- Project affiliation
- Conftest is a utility built on top of Open Policy Agent.openpolicyagent.org · 1 Oct 2026
Best Conftest alternatives
See all 12Where it ranks on Everything Xiaomi
Is Conftest yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- conftest.dev· checked 30 Sept 2026
- conftest.dev/output/· checked 30 Sept 2026
- conftest.dev/options/· checked 30 Sept 2026
- conftest.dev/sharing/· checked 30 Sept 2026
- conftest.dev/plugins/· checked 30 Sept 2026
- conftest.dev/pre_commit/· checked 30 Sept 2026
- conftest.dev/install/· checked 30 Sept 2026
- github.com/open-policy-agent/conftest· checked 30 Sept 2026
- cncf.io/blog/2020/07/23/conftest-joins-the-open· checked 1 Oct 2026
- openpolicyagent.org/ecosystem/entry/conftest· checked 1 Oct 2026
- github.com/open-policy-agent/conftest/blob/master/· checked 1 Oct 2026

