Platform Governance and Guardrails
On this page
Governance Tools
- Admission control policies
- CI policy checks (Conftest)
- Change management via PR reviews
Example: Policy Rule (pseudo)
deny if container.securityContext.privileged == true deny if resources.requests.cpu is missing deny if image tag is "latest" in prod
Exception Process (Operational)
- Exception request as PR with justification
- Auto-expiry date required
- Owner and approver recorded
Failure Modes
- Governance slows teams → bake checks early in CI, not at deploy time only.
- Silent exceptions → require expiry and periodic review.