IaC Policy Gates
You will learn to gate infrastructure changes before apply: evaluating a Terraform plan with Sentinel or conftest, writing custom Checkov checks, and deciding which severities block a PR versus warn. Interviewers ask how you would stop a public S3 bucket at review time, and this is the answer they expect.
on this pageshowhide
explore
- Artifact Under Evaluation17 questions
- Planned Values and Actions4 questions
- Unknown Until Apply3 questions
- Modules Versus Resources3 questions
- Targets Without a Plan4 questions
- Beyond One Resource3 questions
- Custom Rule Authoring12 questions
- Enforcement Decisions8 questions
- After the Apply4 questions
- Suppressing a Finding4 questions
questions
page 2 of 2What does conftest's --combine flag change about the input a rule sees?
basics
~20 sWithout it, each file is evaluated on its own and the input is that file's document. With --combine, all files are merged into one evaluation where the input is an array of elements carrying a path and the file's contents, so rules must iterate rather than address fields directly.
A log-retention rule's subject lives in another root module's plan — how do you gate it?
basics
~20 sUsually you do not gate it here. When the control's subject is missing from this plan, either constrain the module input so it becomes visible, or re-home the control where the subject exists. Approximating it is worse than not enforcing it.
In a Terraform plan, how do you gate a change that lowers a database's backup retention window?
basics
~20 sCompare both sides of the diff. Deny when change.after's retention is lower than change.before's, so an already sub-standard database can be edited for unrelated reasons but never made worse. Creates have no before, so apply the absolute minimum.
It is 02:00 and every apply in HCP Terraform is failing at the policy check — how do you diagnose it?
basics
~20 sRead the policy check output first: a failure across every workspace at once points at the policy set or its inputs, not at anyone's change. Then reproduce offline by downloading a failed run's mock data and evaluating the policy locally.
Your custom Rego rule for Trivy or KICS reports nothing — how do you diagnose it?
basics
~20 sCheck three layers in order: the engine never loaded the file (wrong custom-rule path, or a package namespace the scan does not include), the required metadata is missing so the rule is not registered or graded, and the Rego body is simply undefined — in Rego undefined yields no result, not a failure.
An auditor wants proof that last quarter's policy finding is closed — why isn't the closed ticket enough?
basics
~10 sA ticket records that someone said they fixed it. Proof is the same rule, re-run over current state, no longer returning that resource — shown alongside the earlier run that did return it.
How do you find every live Checkov suppression across your Terraform repos, and spot the stale ones?
basics
~20 sCollect two sources, not one: every inline skip annotation in the source, and every skip-check, skip-path and skip flag in scan configuration and pipeline definitions. Then age each one with git history and the scan's skipped-checks output.
showing 31–37 of 37