Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
4 to work through
-
intermediate
An enterprise wants automated policy enforcement. Where should policies be evaluated, and what makes the approach fail?
1 min answer -
advanced
A platform team's policy-as-code library has 240 rules. 190 are warn-only because teams objected to blocking. Pipeline output runs to 300 lines and nobody reads it. Two recent incidents were caused by conditions that rules 14 and 87 had been warning about for months. Review this. What would you remove, what would you change, and what would you keep?
3 min answer -
advanced
An admission policy requires that every image have a vulnerability scan with no critical findings, and the admission controller calls the scanner's API at admission time to check. The control works. What has the team bought, what are they paying, and when does the bill arrive?
3 min answer -
advanced Multiple choice
Your admission-time policy engine becomes unavailable during a deployment window. Should admission fail open - allow the change - or fail closed - block it?
3 min answer
3 terms in this topic
Admission Policy
A rule evaluated at the moment a resource is created or changed, which rejects the request rather than reporting on it afterwards.
practicePolicy as Code
Expressing organisational rules as executable code evaluated automatically in pipelines and at admission, instead of as prose enforced by review.
conceptPolicy Failure Mode
What an admission-time policy engine does when it cannot be reached - fail open and allow the change, or fail closed and block it - decided per polic…
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.