skip to content

Policy as Code

You will learn to encode security and compliance guardrails as executable policy — Rego and Kyverno rules, admission controllers, and IaC gates that block a bad change in the pipeline. Interviewers probe it because it is how a DevSecOps team stops a non-compliant deploy without a human in the loop.

on this pageshow

explore

questions

363 · 9 sections

In a policy decision, what separates the change under evaluation from the surrounding facts?

level: juniorimportance: must knowfreq 72%
basics
~20 s

The change under evaluation is the document being decided on, such as a proposed plan or manifest. The surrounding facts are everything else the rule needs, like the list of approved instance types, which the change never carries.

open as a page

What do PDP, PEP and PIP each do in a policy-as-code gate?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A policy decision point evaluates the rule and returns an answer. A policy enforcement point sits in the change's path, gathers the input, asks, and acts on the reply. A policy information point supplies facts the change itself does not carry.

open as a page

A CI job enforces backup retention with a shell script that exits 1. What does restating it as a policy rule buy?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A rule file states the condition as data, so the engine can report which rule failed on which resource, and the same rule can be listed, reviewed and reused elsewhere. An exit code carries one bit: pass or fail.

open as a page

A policy gate blocks your deploy with only 'denied by policy' — what should that denial have carried?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A usable denial names the rule that fired, the object and the exact field it failed on, what the rule requires, and one concrete fix. It should list every violation found, not only the first.

open as a page

A deploy tool calls a policy decision service and gets no answer - what do fail-open and fail-closed mean here?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Fail open means the deploy proceeds when the decision service cannot answer; fail closed means it is rejected. Open protects delivery and lets unassessed changes through; closed protects the guardrail and can halt every deploy in the organisation.

open as a page

In Rego, what does a deny rule written as a partial set of messages produce when no input violates it?

level: juniorimportance: must knowfreq 68%
basics
~10 s

It produces the empty set. Each successful evaluation of the rule body adds one message; when nothing matches, there are zero messages, and a runner such as conftest reports that as a pass.

open as a page

In Rego, where does a rule get a fact that the artifact under evaluation does not contain?

level: juniorimportance: must knowfreq 78%
basics
~20 s

A Rego rule cannot invent a fact. It must be loaded into the engine before the query, supplied by the caller inside the query itself, or fetched during evaluation with http.send. Nothing else reaches a rule.

open as a page

Why does a Rego rule written as deny[msg] { ... } fail to parse under OPA v1?

level: juniorimportance: must knowfreq 74%
basics
~20 s

OPA v1 makes if and contains mandatory, so a partial set rule must read deny contains msg if { ... }. The bare v0 head is a parse error, not a deprecation. import rego.v1 opts a single file into v1 syntax on an older engine.

open as a page

In Rego, what is the difference between the input document and the data document?

level: juniorimportance: must knowfreq 80%
basics
~20 s

input is the document the caller sends with a single query, the thing being judged. data is the tree the engine already holds: JSON loaded alongside the policy, plus the virtual documents that rules themselves define.

open as a page

In Rego, what is the difference between an expression that is undefined and one that is false?

level: juniorimportance: must knowfreq 74%
basics
~20 s

False is a value; undefined means Rego found no value at all. Both stop a rule body, but false is an answer, while undefined leaves the rule with no result to emit and no error to report.

open as a page

What does an OPA bundle contain, and what is the revision in its .manifest for?

level: juniorimportance: must knowfreq 66%
basics
~20 s

An OPA bundle is a gzipped tar archive of Rego policy, data files and an optional .manifest. The manifest's revision is an opaque label for that build, reported in OPA's status and decision output so you know which policy decided.

open as a page

What is OPA's data document, and what are the ways facts get loaded into it?

level: juniorimportance: must knowfreq 72%
basics
~20 s

OPA's data document is the in-memory JSON tree of standing facts policies read as data.something, separate from the input being decided. Facts arrive as startup files, inside a bundle OPA polls for, or as pushes to its Data API.

open as a page

What does Gatekeeper's audit controller do, and where does it write what it finds?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Gatekeeper's audit controller periodically re-evaluates objects that already exist in the cluster against every enforced Constraint and records the violations in each Constraint object's own status field. It only reports: it never blocks, deletes or changes anything.

open as a page

What does Gatekeeper's gator test command evaluate, and what must you feed it?

level: juniorimportance: must knowfreq 60%
basics
~20 s

gator test evaluates Gatekeeper policy locally: you hand it ConstraintTemplates, their Constraints, and the Kubernetes objects to review, and it reports which object violated which constraint. It needs no cluster, no kubeconfig and no admission webhook.

open as a page

What does a Gatekeeper Assign resource do, and how does it differ from a Constraint?

level: juniorimportance: must knowfreq 64%
basics
~10 s

A Gatekeeper Assign is a mutator: at admission it writes a value into a field of the incoming object, so the object is stored changed instead of rejected. A Constraint only inspects and denies.

open as a page

When you kubectl apply a Deployment, which admission requests does the API server actually see?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Three separate ones, not one: your Deployment, then the ReplicaSet the deployment controller creates, then one request per Pod from the ReplicaSet controller. Each is admitted on its own, under the controller's identity rather than yours.

open as a page

In Kubernetes, kubectl printed a 'Warning:' line and still created the object - what happened at admission?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A warning is advisory only. The API server returned it in an HTTP Warning response header alongside a response that succeeded, so the object was admitted. Only a denial, which comes back as a failed status, stops the write.

open as a page

Why do cluster-wide Kubernetes admission policies exclude kube-system from their match scope?

level: juniorimportance: must knowfreq 62%
basics
~20 s

The rule was written for tenant workloads, not cluster infrastructure — and the policy engine's own Pods live in a system namespace, so an engine inside its own scope can block the Pods that would replace it.

open as a page

What does a Kubernetes AdmissionReview request contain, and what cluster information is missing from it?

level: juniorimportance: must knowfreq 70%
basics
~20 s

An AdmissionReview request carries one object under review, its previous version on updates, the requesting user and groups, the operation, resource and subresource, and a dryRun flag. It carries no other objects, no cluster state and no history.

open as a page

When should an admission policy reject a Kubernetes manifest instead of silently patching it?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Patch when the fix is behaviour-neutral and the platform owns the value, like adding a missing default. Reject when the compliant form changes what the process sees, such as moving a secret from an environment variable into a mounted file.

open as a page

What does the Kyverno CLI command kyverno apply do with a policy and a manifest file?

level: juniorimportance: must knowfreq 62%
basics
~20 s

kyverno apply reads policy files and resource files from disk and evaluates the rules against them locally, printing pass, fail, skip and warn results. It is a dry run: no cluster is contacted and nothing is admitted.

open as a page

What does a Kyverno PolicyException name, and what does it not switch off?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A Kyverno PolicyException names the policy and the specific rule names it waives, plus a match block selecting which resources the waiver covers. It never disables the policy itself; anything the match block misses is still enforced.

open as a page

What does a Kyverno generate rule do that a validate rule cannot?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A Kyverno generate rule creates a companion object when a trigger appears, such as a default-deny NetworkPolicy in every new namespace. A validate rule can only accept or reject the request; generate supplies the resource instead of demanding it.

open as a page

In a Kyverno mutate rule, what does the +() add-if-not-present anchor do?

level: juniorimportance: must knowfreq 64%
basics
~20 s

The +() anchor in a Kyverno strategic-merge mutate patch sets a field only when the incoming object does not already have it. If the field is already present, the existing value is left alone rather than overwritten.

open as a page

In Kyverno, what does a validate.deny conditions block do that validate.pattern cannot?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A deny block evaluates boolean conditions with operators over the admission request and blocks when they are true. A pattern only asserts the shape a resource must match, so it cannot use operators, compare two fields, or read request metadata.

open as a page

In a Terraform plan JSON, which section shows that one resource references another?

level: juniorimportance: must knowfreq 58%
basics
~10 s

The configuration section. Each resource there carries an expressions object whose references list the addresses it points at. The planned_values section holds only each resource's resolved attribute values and records no links between resources.

open as a page

In a Terraform plan JSON, where do resources declared inside a module appear to a policy rule?

level: juniorimportance: must knowfreq 66%
basics
~20 s

The plan is flattened. Every resource a module declares is expanded into the plan's resource lists under a module-qualified address such as module.network.aws_s3_bucket.flow_logs, so ordinary resource rules fire on module-created resources without knowing modules exist.

open as a page

Why must a Helm chart be rendered before conftest can evaluate its Kubernetes manifests?

level: juniorimportance: must knowfreq 64%
basics
~10 s

A chart's templates are Go template text, not valid YAML, and fields hidden behind conditionals only appear once values are applied. Render the chart first, then evaluate the manifests it produces.

open as a page

In a Terraform plan JSON, how do `planned_values` and `resource_changes` differ for a policy rule?

level: juniorimportance: must knowfreq 72%
basics
~20 s

planned_values is the whole post-apply state, every managed resource including untouched ones. resource_changes is the per-resource diff, carrying the action and the before and after values. A rule over planned_values judges the estate; a rule over resource_changes judges this run.

open as a page

In a Terraform plan, what does an attribute marked "known after apply" mean for a policy rule?

level: juniorimportance: must knowfreq 68%
basics
~20 s

It means the value does not exist yet: the provider or cloud only produces it when the resource is actually created, so the plan holds a placeholder. A policy rule evaluating that attribute has nothing real to test.

open as a page

Why map one TLS-minimum check to clauses in three compliance frameworks instead of writing three checks?

level: juniorimportance: must knowfreq 62%
basics
~10 s

The check is the same engineering fact; only the reporting differs. One check with three mapping edges means one rule to maintain and three audit reports that can never disagree about the same listener.

open as a page

What does it mean to decompose a compliance control into automated checks?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Decomposition turns one control sentence into the separate facts a machine can test. "Audit logging enabled and retained 365 days" becomes distinct checks: a log destination exists, retention is at least 365, tamper-evidence is on, delivery still succeeds.

open as a page

A control report says 98% of database instances are encrypted at rest — what does that number hide?

level: juniorimportance: must knowfreq 63%
basics
~20 s

A pass rate hides its denominator. The 98% counts only instances the check actually enumerated; anything in an account, region or project the tooling never reached sits outside both numbers, so unseen systems are invisible rather than failing.

open as a page

Your 90-day password rotation check passes on every account — what risk does it not cover?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It proves only that passwords change on schedule. It says nothing about phishing, stolen session tokens, or accounts that were never removed. A green control measures the activity someone wrote down, not the attack it was meant to stop.

open as a page

What must an automated backup-retention check record so its result works as audit evidence later?

level: juniorimportance: must knowfreq 63%
basics
~20 s

Each record needs the verdict plus everything that makes it re-checkable: which control it proves, which resource was evaluated, the exact rule version and input it saw, when it ran, and which identity ran it.

open as a page

What is a shadow run of a candidate policy rule, and what does it tell you before you enforce it?

level: juniorimportance: must knowfreq 63%
basics
~20 s

A shadow run evaluates a candidate rule offline against a corpus of real, already-completed changes and records the verdict it would have given each one, without blocking anything. It shows how often the rule fires and on what.

open as a page

Why does a policy rule's test suite need near-miss allow cases, not just deny cases?

level: juniorimportance: must knowfreq 68%
basics
~10 s

Near-miss cases are legitimate inputs sitting just inside the boundary — the changes the rule must let through. Deny cases only prove a rule can refuse something. They never prove it refuses nothing else.

open as a page

What is a policy rule's input contract, and what does it pin down?

level: juniorimportance: must knowfreq 66%
basics
~10 s

The input contract is the written agreement about the document a rule decides over: which step produces it, how it is wrapped, and which fields are guaranteed present. Agree it before writing the rule.

open as a page

Your nightly encryption-at-rest sweep reports zero violations — what must you know before that means anything?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Which ruleset produced the number and what it covered. Zero violations only means the rules that actually loaded found nothing in the resources that were actually enumerated. An empty or replaced ruleset reports exactly the same green.

open as a page

Why is a policy rule repository reviewed, tested and released like application code?

level: juniorimportance: must knowfreq 72%
basics
~20 s

A rule is production code: one bad rule blocks every team's builds at once. Review, tests and CI catch it before it reaches a gate, and give each change an author, a reviewer and a history.

open as a page

What is a break-glass override of a blocking policy gate, and what must it leave behind?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A break-glass override is a pre-authorised, deliberately loud way to ship one change that a policy gate denied, used when waiting is worse than the risk. It must leave a record: who pulled it, which rule, which change, and why.

open as a page

A CI check rejects plans requesting a disallowed instance type, so why do such instances still appear in the account?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A CI check only sees changes that travel through CI. Anyone holding cloud credentials can create the instance from a console session or a local apply, and that route never reaches the check at all.

open as a page

Why is a pull-request policy check advisory when an in-cluster reconciler is the only thing that applies manifests?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Merging is not deploying. The reconciler reads whatever sits on the tracked branch and applies it, without consulting the check that ran on the pull request. The check informs humans; it has no authority over the applier.

open as a page

In a pull request, what is a required check, and what happens if it never reports a result?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A required check must report a passing result before the pull request may merge. An advisory check only posts a result nobody consults. If a required check never reports, the merge stays blocked rather than allowed.

open as a page

A build gate finds no vulnerability scan report attached to an artifact — is that a pass?

level: juniorimportance: must knowfreq 70%
basics
~20 s

No. A missing report is not a clean result, it is an absent one. A gate needs three outcomes — pass, fail, and no usable evidence — and the third must never be folded silently into the first.

open as a page