Information & Communications Technology

Infrastructure as Code Governance with Policy as Code

Establishes policy as code guardrails, automated compliance checks and drift detection so infrastructure changes stay secure and auditable at scale.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Infrastructure teams that once reviewed every cloud change by hand now ship hundreds of Terraform and OpenTofu pull requests a week, and manual review cannot keep pace without becoming a bottleneck or a rubber stamp. This course teaches infrastructure as code governance built on policy as code: encoding security, cost and compliance rules so they run automatically against every proposed change. Participants learn to write and test Open Policy Agent rules in Rego, wire policy checks into continuous integration pipelines with clear block-or-warn behaviour, and map compliance framework controls to machine-checkable policies with defensible audit evidence. Sessions include hands-on labs building a policy library from scratch, configuring pipeline gates against a sample infrastructure repository, and designing an exception workflow for legitimate one-off deviations. Participants finish with a working policy library, a control traceability matrix template, and a governance metrics dashboard design they can adapt to their own cloud environment and reporting cadence.

Expected Learning Outcomes

01

Design guardrails and approval gates that enforce consistent, secure infrastructure deployments.

02

Write and test Open Policy Agent rules that block non-compliant resource configurations automatically.

03

Integrate policy checks into continuous integration pipelines with clear block-or-warn severity rules.

04

Map compliance framework controls to machine-checkable policies with auditable traceability.

05

Embed cost estimation and budget policies into infrastructure pull request reviews.

06

Detect and remediate configuration drift between declared code and live infrastructure.

07

Operate a multi-team module registry with versioning, access control and deprecation planning.

Who Should Attend

01

Platform engineers building shared infrastructure as code modules for multiple product teams.

02

Cloud security engineers responsible for enforcing configuration and compliance standards.

03

DevOps engineers introducing automated policy checks into existing deployment pipelines.

04

Site reliability engineers accountable for infrastructure change safety and drift control.

05

Compliance and audit specialists who must evidence infrastructure control effectiveness.

06

Engineering leads scaling infrastructure as code practice across several cloud accounts.

Course Modules

Select any module to see its sessions and points.

01

Foundations of Infrastructure as Code Governance

2 sessions · 8 points

Session 1Establishing Guardrails for Infrastructure Code

  • Define governance objectives spanning security, cost, compliance and configuration consistency.
  • Map cloud provider services that require mandatory controls before teams can provision them.
  • Build a golden path module library with pinned versions that teams reuse by default.
  • Decide which policy classes act as hard gates and which act as advisory guardrails.

Session 2State Management and Change Control

  • Configure remote state backends with locking to prevent concurrent, conflicting writes.
  • Structure workspaces and environments so a faulty change has a limited blast radius.
  • Review infrastructure change plans line by line before any apply reaches production.
  • Enforce mandatory peer review on every infrastructure pull request regardless of size.
02

Writing and Enforcing Policy as Code

2 sessions · 8 points

Session 1Authoring Policies with Open Policy Agent and Rego

  • Write Rego policies that deny resource configurations violating agreed standards.
  • Structure policy libraries by domain, separating security, cost and tagging rules.
  • Unit test policies against sample configurations before releasing them to pipelines.
  • Version and release policy changes independently from the infrastructure code they govern.

Session 2Pipeline Gates and Exception Handling

  • Integrate policy checks into continuous integration pipelines alongside plan and lint stages.
  • Classify policy findings by severity to decide automatic block versus warning behaviour.
  • Design a time-boxed exception workflow that records compensating controls and an expiry date.
  • Report policy violation trends to platform and security stakeholders on a fixed cadence.
03

Compliance, Cost and Security Alignment

2 sessions · 8 points

Session 1Mapping Compliance Frameworks to Infrastructure Controls

  • Translate CIS benchmark and ISO/IEC 27001 controls into machine-checkable policy rules.
  • Maintain a control-to-policy traceability matrix that auditors can follow directly.
  • Automate evidence collection so recurring compliance reporting stops relying on manual screenshots.
  • Resolve overlap between multiple compliance frameworks without duplicating policy logic.

Session 2Cost Governance and Drift Detection

  • Embed cost estimation tooling into pull request reviews before infrastructure is provisioned.
  • Set budget policies that block deployments forecast to exceed an agreed spending threshold.
  • Run scheduled drift detection comparing declared code against the live infrastructure state.
  • Remediate detected drift by updating code rather than making manual console changes.
04

Scaling Governance Across Teams and Clouds

2 sessions · 8 points

Session 1Multi-Team Module Registries and Access Control

  • Publish reusable modules through an internal registry using semantic versioning.
  • Apply role-based access control that separates module authors, reviewers and approvers.
  • Manage secrets referenced by infrastructure code through a dedicated secrets manager.
  • Coordinate breaking module changes with consumers through a documented deprecation timeline.

Session 2Governance Metrics and Continuous Improvement

  • Track policy pass rate, exception volume and mean time to remediate violations over time.
  • Run periodic policy effectiveness reviews jointly with security and platform teams.
  • Retire obsolete policies that no longer reflect the current architecture or risk profile.
  • Build a roadmap for extending policy as code coverage to additional cloud platforms.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course