INFRA-DEVOPS Contents

Platform Governance and Guardrails

Governance is guardrails, not bureaucracy. Enforce safe defaults with policy-as-code and provide exceptions with expiration.

On this page

Governance Tools

  • Admission control policies
  • CI policy checks (Conftest)
  • Change management via PR reviews

Example: Policy Rule (pseudo)

deny if container.securityContext.privileged == true
deny if resources.requests.cpu is missing
deny if image tag is "latest" in prod

Exception Process (Operational)

  • Exception request as PR with justification
  • Auto-expiry date required
  • Owner and approver recorded

Failure Modes

  • Governance slows teams → bake checks early in CI, not at deploy time only.
  • Silent exceptions → require expiry and periodic review.