Policy as Code
Kind: mechanism
Layer: Security Core
Record: architecture:policy-as-code
Severity: recommended
Scope: infrastructure, deployment, security
Canonical: Ontology
A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.
Listed in Architecture principles, after Policy Enforcement and before Risk Management.
Requires
Reinforces
Enables
Conflicts with
In tension with
Tensions
Violated by
Refactored by
Severity
Category
Enforced by
- rules/eslint/closure-no-disable-comments.eslint.rule.ts
- rules/eslint/closure-rule-shape.eslint.rule.ts
Refactors
- Security Theater
- Authorization Scattering
- Control Plane
- Attribute-Based Access Control
- Policy Enforcement
Linked from
- Writing constraints
- Three encodings
- Where a rule lives
- From intent to predicate
- Anti-patterns
- Control / Coordination / Centralization
- Portability / Infrastructure / Deployment
- Observability / Auditability / Traceability
- Security / Privacy / Compliance / Governance
- Core Vocabulary
- Security Privacy Compliance
- Severity levels
- The resolutions