Conftest
About
Conftest is a utility for testing structured configuration data, with a focus on configuration checks in CI environments. It uses Open Policy Agent's Rego language to define policies and evaluates deny, violation, and warning rules within namespaces. Inputs can be supplied as files, directories, multiple files, or standard input. Supported data includes Kubernetes-style YAML, JSON, HCL and HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, XML, and other documented formats. Results can be emitted as plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps, or SARIF; the GitHub outputter can annotate workflow results. The `conftest verify` command runs policy unit tests. Policies can be pulled from HTTPS URLs, Git repositories, and OCI registries, then pushed to compatible OCI registries. Plugins extend the CLI, with downloads available from sources including OCI, Git, HTTP/HTTPS, Mercurial, Amazon S3, and Google Cloud Storage. Conftest also provides pre-commit hooks and documents CI integrations. It is available for Linux, macOS, and Windows.
Who it is for
Conftest suits teams that need policy-based tests for structured configuration in CI. It is built on Open Policy Agent and supports a range of configuration formats and output targets.
What is good
- Uses Rego policies and supports namespaces.
- Tests files, directories, multiple files, or standard input.
- Offers GitHub, Azure DevOps, JUnit, and SARIF outputs.
- Policies can be shared through Git and OCI registries.
- Pre-commit hooks cover policy workflows.
What to know first
- The instrumenta/conftest container image is deprecated.
- Community questions are directed to the Open Policy Agent Slack channel.
Verdict
Conftest brings configuration policy checks, policy unit tests, and CI-oriented output formats into one utility. Teams should use the documented openpolicyagent/conftest image rather than the deprecated instrumenta image.
Compared on infrastructure testing tools
- Free plan
- Yesconftest.dev
- Terraform analysis
- Yesconftest.dev
- Kubernetes analysis
- Yesconftest.dev
- Custom policies
- Yesconftest.dev
- Pull request scanning
- Yesconftest.dev
Facts
- Purpose
- Conftest is a utility for writing tests against structured configuration data.conftest.dev · 30 Sept 2026
- Policy language
- Conftest uses the Open Policy Agent Rego language for writing policies.conftest.dev · 30 Sept 2026
- Target users
- Conftest is designed for configuration testing in CI environments.conftest.dev · 30 Sept 2026
- Supported formats
- Supported inputs include Kubernetes-style YAML, JSON, HCL/HCL2, Dockerfiles, Terraform-related data, JSONnet, TOML, XML, and other formats listed in the documentation.conftest.dev · 30 Sept 2026
- Policy rules
- Conftest evaluates deny, violation, and warn rules and supports namespaces.conftest.dev · 30 Sept 2026
- Input methods
- Configuration can be tested from files, directories, multiple files, or standard input.conftest.dev · 30 Sept 2026
- CI outputs
- Output formats include JSON, TAP, table, JUnit, GitHub, Azure DevOps, and SARIF.conftest.dev · 30 Sept 2026
- GitHub integration
- The GitHub outputter can annotate configuration test results for GitHub workflows.conftest.dev · 30 Sept 2026
- Policy sharing
- Policies can be pulled from HTTPS URLs, Git repositories, and OCI registries, and pushed to compatible OCI registries.conftest.dev · 30 Sept 2026
- Plugin system
- Plugins can extend the Conftest CLI and can be downloaded through OCI, local files, Git, HTTP/HTTPS, Mercurial, Amazon S3, or Google Cloud Storage.conftest.dev · 30 Sept 2026
- Pre-commit
- Conftest provides pre-commit hooks for testing, verifying, documenting, pulling, and formatting policies.conftest.dev · 30 Sept 2026
- Release security
- Every release asset, checksums file, and container image is attested with GitHub artifact attestations using SLSA provenance signed through Sigstore.conftest.dev · 30 Sept 2026
- Deployment options
- Conftest can be installed with Homebrew, Scoop, Mise, Docker, or from source.conftest.dev · 30 Sept 2026
- Deprecated image
- The instrumenta/conftest container image is deprecated and the documentation directs users to openpolicyagent/conftest.conftest.dev · 30 Sept 2026
- Community support
- The project directs discussions and questions to the Open Policy Agent Slack #opa-conftest channel.github.com · 30 Sept 2026
- Configuration targets
- Conftest supports Kubernetes configurations, Tekton pipeline definitions, Terraform code, Serverless configurations and other structured data.conftest.dev · 1 Oct 2026
- Policy testing
- The `conftest verify` command executes policy unit tests and reports their results.conftest.dev · 1 Oct 2026
- Output formats
- Conftest supports plaintext, JSON, TAP, table, JUnit, GitHub, Azure DevOps and SARIF output.conftest.dev · 1 Oct 2026
- Plugins
- Conftest plugins extend the CLI and can be downloaded from OCI registries, local files, Git, HTTP/HTTPS, Mercurial, Amazon S3 and Google Cloud Storage.conftest.dev · 1 Oct 2026
- CI integration
- The project documents integrations with CircleCI, GitHub Actions and Tekton Pipelines.cncf.io · 1 Oct 2026
- Support
- Questions and discussions are directed to the Open Policy Agent Slack channel `#opa-conftest`.github.com · 1 Oct 2026
- Project affiliation
- Conftest is a utility built on top of Open Policy Agent.openpolicyagent.org · 1 Oct 2026
Best Conftest alternatives
See all 12
7.2 AWS CloudFormation Free free plan, no paid price published Free plan
7.2 Chef InSpec Free free plan, no paid price published Free plan
6.8 CIS-CAT Pro Assessor $200/mo first paid tier
6.0 Terratest Free free plan, no paid price published Free plan
5.9 cfn-lint Free free plan, no paid price published Free plan
5.9 Cinc Auditor Free free plan, no paid price published Free plan Where it ranks on Inferse
Sources
- conftest.dev· checked 30 Sept 2026
- conftest.dev/output/· checked 30 Sept 2026
- conftest.dev/options/· checked 30 Sept 2026
- conftest.dev/sharing/· checked 30 Sept 2026
- conftest.dev/plugins/· checked 30 Sept 2026
- conftest.dev/pre_commit/· checked 30 Sept 2026
- conftest.dev/install/· checked 30 Sept 2026
- github.com/open-policy-agent/conftest· checked 30 Sept 2026
- cncf.io/blog/2020/07/23/conftest-joins-the-open· checked 1 Oct 2026
- openpolicyagent.org/ecosystem/entry/conftest· checked 1 Oct 2026
- github.com/open-policy-agent/conftest/blob/master/· checked 1 Oct 2026



