IaC Policies
OPA policy definitions and evaluation rules for HCA infrastructure, published to Artifactory and consumed by terraform infrastructure repositories.
Policy domains
- IAM: Identity and Access Management
- STR: Storage Services
- CMP: Compute Services
- NCD: Networking and Content Delivery
- DAT: Database Services
- EKM: Encryption and Key Management
- LOM: Logging, Observability, and Monitoring
- ORG: Organizations and Accounts
- GAC: Governance and Compliance
Commands
# Format rego policy files in place
opa fmt --write policies/
# Verify formatting is correct
opa check --strict policies/
# Build the policy bundle
opa build ./policies -o policies-bundle.tar.gz
# Validate policy catalog
opa eval --data policies/ --format raw "data.validate.deny[_].summary"
# Evaluate plan against policies (using policy files)
opa eval --input test/tfplan.json --data policies/ --data test/governance.json --format raw "data.evaluate.deny[_].summary"
opa eval --input test/tfplan.json --data policies/ --data test/governance.json --format raw "data.evaluate.warn[_].summary"
# Evaluate plan against policies (using bundle)
opa eval --input test/tfplan.json --bundle policies-bundle.tar.gz --data test/governance.json --format raw "data.evaluate.deny[_].summary"
opa eval --input test/tfplan.json --bundle policies-bundle.tar.gz --data test/governance.json --format raw "data.evaluate.warn[_].summary"
# Output violations to file
opa eval --input test/tfplan.json --data policies/ --data test/governance.json --format pretty "data.evaluate.deny" > violations.deny.json
opa eval --input test/tfplan.json --data policies/ --data test/governance.json --format pretty "data.evaluate.warn" > violations.warn.json
Getting started
Run the workspace bootstrap script before working on this repository.
.\scripts\workspace-bootstrap.ps1
Commit messages
Follow conventional commit standards using the helper script.
.\scripts\conv-commit.ps1
Format: type(scope): description
Types: feat, fix, chore, docs, refactor, revert
Branch naming
Prefix your branch with the primary type of change. Examples: feat/add-vpc-stack, fix/correct-subnet-cidr
Pull requests
- Open a PR from your feature branch into
main - Fill in the PR template completely
- Assign at least one reviewer
- Ensure all checks pass before requesting approval
- You are responsible for merging once approved