WeAreDevelopers LIVE β€’ Oct 19, 2022

Policy as [versioned] code - you're doing it wrong

Chris Nesbitt-Smith

Writing rules in YAML isn't true policy as code. Stop breaking CI pipelines and start treating compliance as a visible, version-controlled software dependency.

Pause
Mute Enter Fullscreen
#1 about 5 min

Elevator pitch analogy for policy management

A fictional elevator scenario illustrates the pain points of policy enforcement among executives, product managers, and developers.

#2 about 4 min

Core promises of policy as versioned code

Treating policy as a versioned dependency enables faster updates, local compliance checks, and clear communication.

#3 about 4 min

Common pitfalls in implementing policy as code

Hiding security policies from developers leads to reverse-engineered constraints, broken deployments, and brittle case law exemptions.

#4 about 5 min

Managing policies exactly like standard software dependencies

Making policy source code visible and applying semantic versioning allows automatic compliance updates via standard continuous integration tools.

#5 about 5 min

Code demonstration using terraform and kubernetes

Evaluating semantic policy versions systematically across environments relies on localized validation and active admission controllers.

#6 about 4 min

Connecting policy rules directly to business risk

Policies must carry a clear risk narrative to prevent agile product teams from treating them as unnecessary friction.

#7 about 2 min

Addressing cultural resistance to compliance policy controls

Tangible risk communication prevents teams from viewing essential policies as bureaucratic hurdles.

#8 about 2 min

Evaluating risk scenarios across cheaper cloud providers

Using smaller cloud vendors instead of major players requires carefully understanding the organizational risk appetite.

#9 about 2 min

Row and cell level database encryption tradeoffs

Advanced database encryption methods must be proportional to risk due to the complexity of underlying key management and incident recovery.

#10 about 2 min

Presentation design and open source markdown tools

Markdown-based HTML presentation formats allow for rapid pacing and easy open source technical content generation.

#11 about 3 min

Usability and syntax challenges with rego and opa

Complex policy languages heavily prioritize performance over developer readability and require strict testing structures for validation.

#12 about 4 min

Mitigating software supply chain vulnerabilities with speed

Treating patch deployments like regular feature releases maintains rapid delivery while lowering third-party software supply chain dependency risks.

#13 about 5 min

Bridging engineering constraints and public sector governance

Brokering risk conversations in public systems involves translating abstract technology risks into concrete business trade-offs.

#14 about 4 min

Evaluating proportional security isolation and sandbox tactics

No environment is completely secure, meaning isolation tactics like sandboxing only represent one end of the overarching cost and risk spectrum.

#15 about 3 min

Expanding on policy as code methodology concepts

Contributing to open source thought leadership helps challenge current industry paradigms around infrastructure management and versioning.

Matching moments

1:22 min

Enforcing policy validations in continuous integration pipelines

Philipp Krenn Β· World Congress 2023

7:07 min

Implementing programmatic policy checks with Open Policy Agent

Madhu Akula Β· LIVE

2:31 min

Enforcing compliance with guardrails and policy as code

Martin Reynolds Martin Reynolds Β· World Congress 2025

4:48 min

Automating customized policy enforcement with open source tools

Noaa Barki Β· World Congress 2022

3:01 min

Balancing coding productivity with enterprise data governance pipelines

Thomas Froment Thomas Froment Β· World Congress 2026 Europe

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis Β· World Congress 2024