The author describes using conftest, a policy-as-code tool built on Open Policy Agent, to evaluate Terraform plans programmatically and deterministically. Terraform exports its plan as JSON, which conftest tests against Rego policies. This approach enables auditable, testable, and reproducible auto-apply without relying on non-deterministic AI review.
Tap to vote and see what everyone thinks.
Critical IAM Priorities In The Age Of Machine Identities
Summary by ByteBrief