DevOps/CloudSecurity

Policy as Code

Also written as Open Policy Agent, OPA, Rego, Kyverno

Writing an organisation's rules, such as 'no public storage buckets' or 'every container must come from our registry', as code that is checked automatically in pipelines and clusters, instead of in a document people are meant to follow. Open Policy Agent (OPA, using its Rego language) and Kyverno are the common tools.

Think of it like

A turnstile that checks tickets automatically instead of a sign saying 'tickets required'.

Junior or senior?

Signals a mature platform or security team.

Senior sounds like

Can describe rolling a policy out in warning-only mode first and handling the teams it would have broken.

Ask them

“Which policy did you enforce, and how did you roll it out without blocking every team on day one?”