Chapter 1. Policy as Code: A Gentle Introduction
By some estimates, more than 2.7 trillion lines of code have been written in the last 60-plus years. How many lines have you written? I don’t know how many lines I’ve written, but I’ve been writing code for almost 30 years. Only in the last eight years have I used Policy as Code (PaC) to control changes better, guide me through complex systems and solutions, and ensure that what I write is what I mean to write, execute, and distribute.
Regardless of system or artifact, PaC has emerged as the standard for how we reduce unwanted and nondeterministic changes and behaviors across the systems and solutions we use, build, and support. PaC allows us to codify the guidelines we specify, follow, and impose. PaC inherits its utility from coding standards and best practices as well as the controls to implement them.
PaC shows up in and improves many systems and solutions today, ranging from cloud computing and Kubernetes to Authorization (AuthZ), continuous integration/continuous delivery (CI/CD), DevOps, DevSecOps, GitOps, and software supply chain security. In this book, I examine PaC more closely and present ideas, patterns, and examples of how to use PaC to policy-enable your solutions. For now, in this chapter I introduce PaC concepts, how PaC should trace from your standards, and the characteristics of PaC that can be used to help you choose the right solution for your needs. By chapter’s end, you will have a process and a checklist ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access