Prompt
How do I enforce policy as code for infrastructure changes?
Latest observation
To enforce policy as code for infrastructure changes, you want a setup where every proposed change is automatically checked against your rules before it can be merged or applied.
Core idea
Treat infrastructure definitions as code, then evaluate them with policy rules during the delivery pipeline.
Typical flow:
-
Developer changes IaC
- Terraform, CloudFormation, Pulumi, Kubernetes manifests, etc.
-
CI validates the change
- Syntax/linting
- Security scanning
- Policy checks
-
Policy engine evaluates rules
- Example rules:
- No public S3 buckets
- All resources must be tagged
- Only approved instance types
- Encryption must be enabled
- No privileged Kubernetes pods
- Example rules:
-
Block or allow
- Fail the pipeline if a rule is violated
- Optionally auto-remediate or require approval
Common tools
Depending on your stack:
General policy engines
- OPA (Open Policy Agent) with Conftest
- HashiCorp Sentinel for Terraform/HashiCorp stack
- Kyverno for Kubernetes admission policies
- Gatekeeper (OPA-based) for Kubernetes
- AWS Config / Azure Policy / GCP Organization Policy for cloud-native enforcement
IaC-specific integrations
- Terraform
- Sentinel
- OPA + Conftest
- Terraform Cloud/Enterprise policy checks
- Kubernetes
- Kyverno or Gatekeeper
- Admission controllers
- Cloud runtime
- AWS Config rules
- Azure Policy
- GCP Policy Controller
Recommended enforcement layers
Use more than one layer:
1. Pre-merge / CI checks
Catch violations early.
- Run policy tests on pull requests
- Validate the planned infrastructure changes, not just the code
2. Deployment-time checks
Prevent bad changes from being applied.
- CI/CD pipeline gate
- Terraform Cloud policy enforcement
- Kubernetes admission control
3. Runtime governance
Detect drift and noncompliance after deployment.
- Cloud security posture tools
- Config compliance rules
- Continuous monitoring
Example with OPA + Conftest
If you use Terraform, a common pattern is:
- Generate a Terraform plan in JSON
- Feed it to Conftest
- Write Rego policies
- Fail the pipeline if policy violations exist
Example policy
package main
deny[msg] {
input.resource_type == "aws_s3_bucket"
input.config.acl == "public-read"
msg := "S3 buckets must not be public"
}
CI command
terraform plan -out=tfplan
terraform show -json tfplan > tfplan.json
conftest test tfplan.json
Example with Terraform Sentinel
Sentinel is commonly used in Terraform Cloud/Enterprise:
- Write policy in Sentinel language
- Attach policies to workspaces or policy sets
- Enforce at plan/apply time
- Can do soft mandatory, hard mandatory, or advisory policies
Example with Kubernetes
For Kubernetes workloads:
- Use Kyverno for simple YAML-friendly policies
- Use Gatekeeper if you prefer OPA/Rego
Example policy goals:
- Deny privileged containers
- Require resource limits
- Require labels/annotations
- Block hostPath mounts
These run as admission controllers, so bad manifests are rejected before they reach the cluster.
Best practices
- Policy on the plan, not just the config
- Especially for Terraform, evaluate the planned change output
- Version control policies
- Store policies in Git with code review
- Keep rules small and testable
- One policy per concern
- Use exceptions sparingly
- If needed, make them explicit and auditable
- Start with high-risk controls
- Public exposure, encryption, IAM permissions, logging, tagging
- Report clearly
- Developers need understandable failure messages
- Automate remediation where possible
- For runtime drift, trigger alerts or fixes
A practical implementation pattern
If you want a simple, effective setup:
- Terraform: OPA/Conftest in CI + Terraform Cloud policy checks if available
- Kubernetes: Kyverno or Gatekeeper
- Cloud posture: AWS Config / Azure Policy / GCP Policy Controller
- GitHub Actions / GitLab CI / Jenkins: enforce policy before merge
Minimal rollout plan
- Identify 5–10 critical policies
- Encode them in OPA/Sentinel/Kyverno
- Add CI enforcement on pull requests
- Make failures blocking
- Add runtime compliance checks
- Expand policy coverage over time
If you tell me what infrastructure you use — for example Terraform + AWS, Kubernetes, or Azure — I can give you a concrete reference architecture and sample policies.