skip to content

IaC Policy Gates

You will learn to gate infrastructure changes before apply: evaluating a Terraform plan with Sentinel or conftest, writing custom Checkov checks, and deciding which severities block a PR versus warn. Interviewers ask how you would stop a public S3 bucket at review time, and this is the answer they expect.

on this pageshow

explore

questions

page 2 of 2

What does conftest's --combine flag change about the input a rule sees?

level: middleimportance: nice to knowfreq 30%

basics

~20 s

Without it, each file is evaluated on its own and the input is that file's document. With --combine, all files are merged into one evaluation where the input is an array of elements carrying a path and the file's contents, so rules must iterate rather than address fields directly.

open as a page

A log-retention rule's subject lives in another root module's plan — how do you gate it?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Usually you do not gate it here. When the control's subject is missing from this plan, either constrain the module input so it becomes visible, or re-home the control where the subject exists. Approximating it is worse than not enforcing it.

open as a page

In a Terraform plan, how do you gate a change that lowers a database's backup retention window?

level: seniorimportance: nice to knowfreq 36%

basics

~20 s

Compare both sides of the diff. Deny when change.after's retention is lower than change.before's, so an already sub-standard database can be edited for unrelated reasons but never made worse. Creates have no before, so apply the absolute minimum.

open as a page

It is 02:00 and every apply in HCP Terraform is failing at the policy check — how do you diagnose it?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

Read the policy check output first: a failure across every workspace at once points at the policy set or its inputs, not at anyone's change. Then reproduce offline by downloading a failed run's mock data and evaluating the policy locally.

open as a page

Your custom Rego rule for Trivy or KICS reports nothing — how do you diagnose it?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Check three layers in order: the engine never loaded the file (wrong custom-rule path, or a package namespace the scan does not include), the required metadata is missing so the rule is not registered or graded, and the Rego body is simply undefined — in Rego undefined yields no result, not a failure.

open as a page

An auditor wants proof that last quarter's policy finding is closed — why isn't the closed ticket enough?

level: seniorimportance: nice to knowfreq 31%

basics

~10 s

A ticket records that someone said they fixed it. Proof is the same rule, re-run over current state, no longer returning that resource — shown alongside the earlier run that did return it.

open as a page

How do you find every live Checkov suppression across your Terraform repos, and spot the stale ones?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Collect two sources, not one: every inline skip annotation in the source, and every skip-check, skip-path and skip flag in scan configuration and pipeline definitions. Then age each one with git history and the scan's skipped-checks output.

open as a page

showing 31–37 of 37