WeAreDevelopers LIVE Oct 19, 2022

Policy as [versioned] code - you're doing it wrong

Chris Nesbitt-Smith

Writing rules in YAML isn't true policy as code. Stop breaking CI pipelines and start treating compliance as a visible, version-controlled software dependency.

Pause
Mute Enter Fullscreen
#1 about 5 min

Elevator pitch analogy for policy management

A fictional elevator scenario illustrates the pain points of policy enforcement among executives, product managers, and developers.

#2 about 4 min

Core promises of policy as versioned code

Treating policy as a versioned dependency enables faster updates, local compliance checks, and clear communication.

#3 about 4 min

Common pitfalls in implementing policy as code

Hiding security policies from developers leads to reverse-engineered constraints, broken deployments, and brittle case law exemptions.

#4 about 5 min

Managing policies exactly like standard software dependencies

Making policy source code visible and applying semantic versioning allows automatic compliance updates via standard continuous integration tools.

#5 about 5 min

Code demonstration using terraform and kubernetes

Evaluating semantic policy versions systematically across environments relies on localized validation and active admission controllers.

#6 about 4 min

Connecting policy rules directly to business risk

Policies must carry a clear risk narrative to prevent agile product teams from treating them as unnecessary friction.

#7 about 2 min

Addressing cultural resistance to compliance policy controls

Tangible risk communication prevents teams from viewing essential policies as bureaucratic hurdles.

#8 about 2 min

Evaluating risk scenarios across cheaper cloud providers

Using smaller cloud vendors instead of major players requires carefully understanding the organizational risk appetite.

#9 about 2 min

Row and cell level database encryption tradeoffs

Advanced database encryption methods must be proportional to risk due to the complexity of underlying key management and incident recovery.

#10 about 2 min

Presentation design and open source markdown tools

Markdown-based HTML presentation formats allow for rapid pacing and easy open source technical content generation.

#11 about 3 min

Usability and syntax challenges with rego and opa

Complex policy languages heavily prioritize performance over developer readability and require strict testing structures for validation.

#12 about 4 min

Mitigating software supply chain vulnerabilities with speed

Treating patch deployments like regular feature releases maintains rapid delivery while lowering third-party software supply chain dependency risks.

#13 about 5 min

Bridging engineering constraints and public sector governance

Brokering risk conversations in public systems involves translating abstract technology risks into concrete business trade-offs.

#14 about 4 min

Evaluating proportional security isolation and sandbox tactics

No environment is completely secure, meaning isolation tactics like sandboxing only represent one end of the overarching cost and risk spectrum.

#15 about 3 min

Expanding on policy as code methodology concepts

Contributing to open source thought leadership helps challenge current industry paradigms around infrastructure management and versioning.

Matching moments

1:22 min

Enforcing policy validations in continuous integration pipelines

Philipp Krenn · World Congress 2023

7:07 min

Implementing programmatic policy checks with Open Policy Agent

Madhu Akula · LIVE

2:31 min

Enforcing compliance with guardrails and policy as code

Martin Reynolds Martin Reynolds · World Congress 2025

4:48 min

Automating customized policy enforcement with open source tools

Noaa Barki · World Congress 2022

3:01 min

Balancing coding productivity with enterprise data governance pipelines

Thomas Froment Thomas Froment · World Congress 2026 Europe

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · World Congress 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 12:20–12:50

Stage 4

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 23, 2026 · 14:00–14:30

Stage 1

Supply Chain Security When Agents Write the Code

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 24, 2026 · 09:45–10:15

Mainstage

Manufacturing trust: speed and safety in the age of agents

Mark Cavage

Mark Cavage President and COO of Docker

Mark Cavage
Open session

World Congress 2026 North America

September 25, 2026 · 11:00–11:30

Mainstage

Govern the Runtime, Not the Agent: One Control Plane for Every Model, Every Harness

Tushar Jain

Chief Technology Officer, Docker

Tushar Jain
Open session

World Congress 2026 North America

September 24, 2026 · 10:20–10:50

Stage 2

From Static Rules to Reasoning Platforms: Scaling Intelligent Canary Delivery in 2026

Daniel Oh

Senior Principal Developer Advocate

Daniel Oh