<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0"><channel><title>Pulumi Blog: Compliance</title><link>https://www.pulumi.com/blog/tag/compliance/</link><description>Pulumi blog posts: Compliance.</description><language>en-us</language><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><item><title>Enforce ISO 27001 Across Your AWS Infrastructure</title><link>https://www.pulumi.com/blog/iso-27001-policy-pack-for-aws/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/iso-27001-policy-pack-for-aws/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/iso-27001-policy-pack-for-aws/index.png" /&gt;
&lt;p&gt;ISO/IEC 27001 is the international standard for information security management. Proving you meet it usually means months of mapping abstract security controls to concrete cloud configuration, then authoring custom checks one resource at a time. We&amp;rsquo;re changing that.&lt;/p&gt;
&lt;p&gt;Today we&amp;rsquo;re shipping a pre-built ISO/IEC 27001:2022 policy pack for AWS, live now in Pulumi Cloud as &lt;code&gt;iso-27001-aws&lt;/code&gt;. It encodes the standard&amp;rsquo;s security expectations as 238 ready-to-run policies, so you can align your AWS estate to ISO 27001 in minutes, not months.&lt;/p&gt;
&lt;h2 id="why-iso-27001-matters"&gt;Why ISO 27001 matters&lt;/h2&gt;
&lt;p&gt;For many companies, ISO 27001 is what stands between them and a customer or a market. The sooner you can reach a certifiable state and prove you stay there, the less compliance slows the business down. The pack collapses months of policy work into something you run continuously, so security keeps pace with growth instead of blocking it.&lt;/p&gt;
&lt;h2 id="how-the-pack-maps-to-iso-27001"&gt;How the pack maps to ISO 27001&lt;/h2&gt;
&lt;p&gt;The hard part of ISO 27001 has always been translation: its controls are written in the language of governance and risk management, not in the language of AWS resources. Every team has had to interpret each control and decide what it means for an S3 bucket or an RDS instance.&lt;/p&gt;
&lt;p&gt;The pack does that interpretation for you. Its 238 policies are aligned to the relevant ISO 27001 controls, so each result connects back to the standard instead of leaving you to map it yourself. You can browse the full pack in the &lt;a href="https://www.pulumi.com/docs/reference/pre-built-policy-packs/iso-27001/aws/"&gt;pack reference&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="audit-and-prevent"&gt;Audit and prevent&lt;/h2&gt;
&lt;p&gt;The same pack works two ways, so you can both reach compliance and stay there:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Audit.&lt;/strong&gt; Scan your existing AWS estate against the pack, including resources that Pulumi doesn&amp;rsquo;t manage. You get an honest baseline of where you stand against ISO 27001 today, with every finding tied back to the control it affects.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prevent.&lt;/strong&gt; Run the same pack as a preventative policy during &lt;code&gt;pulumi up&lt;/code&gt; to block non-compliant resources before they&amp;rsquo;re ever created. New infrastructure is born aligned to the standard.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Audit gets you clean. Preventative policies keep you clean.&lt;/p&gt;
&lt;h2 id="a-growing-library-of-pre-built-packs"&gt;A growing library of pre-built packs&lt;/h2&gt;
&lt;p&gt;ISO 27001 joins a growing library of pre-built packs for AWS, each authored and maintained by Pulumi and kept current with its source standard:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;ISO/IEC 27001:2022&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CIS Controls v8.1&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PCI DSS v4.0&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HITRUST CSF v11.5&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Pulumi Best Practices&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Adopting any pack means you skip the authoring work entirely, inherit framework mappings maintained by Pulumi, and apply a consistent baseline across every stack and account.&lt;/p&gt;
&lt;h2 id="get-started-today"&gt;Get started today&lt;/h2&gt;
&lt;p&gt;The ISO 27001 pack is available now to every Pulumi Cloud user:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Browse the &lt;a href="https://www.pulumi.com/docs/reference/pre-built-policy-packs/iso-27001/aws/"&gt;pack reference&lt;/a&gt; to see all 238 policies and how they map to the standard&amp;rsquo;s controls.&lt;/li&gt;
&lt;li&gt;Explore the full &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/pre-built-packs/"&gt;pre-built packs index&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Follow the &lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;get-started guide&lt;/a&gt; to run your first audit.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi policies&lt;/h2&gt;
&lt;p&gt;Ready to align your AWS infrastructure to ISO 27001? &lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and run the pack against your estate, or read the &lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;policy get-started guide&lt;/a&gt; to dig in.&lt;/p&gt;
&lt;p&gt;Need a compliance pack for a framework that isn&amp;rsquo;t listed here? Open a request in &lt;a href="https://github.com/pulumi/pulumi-cloud-requests"&gt;pulumi/pulumi-cloud-requests&lt;/a&gt; or come tell us in the &lt;a href="https://slack.pulumi.com/"&gt;community Slack&lt;/a&gt;. We&amp;rsquo;re listening.&lt;/p&gt;</description><author>Dan Biwer</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>compliance</category><category>governance</category><category>security</category></item><item><title>Enforce AWS Organizations Tag Policies with Pulumi</title><link>https://www.pulumi.com/blog/aws-organizations-tag-policies/</link><pubDate>Thu, 20 Nov 2025 10:00:00 -0800</pubDate><guid>https://www.pulumi.com/blog/aws-organizations-tag-policies/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/aws-organizations-tag-policies/index.png" /&gt;
&lt;p&gt;Tags are the foundation of cloud governance, enabling cost allocation, ownership tracking, compliance reporting, and automation across your AWS infrastructure. Yet missing or inconsistent tags remain one of the most common governance challenges. Manual tag enforcement is error-prone, and discovering missing tags after deployment means your cost reports and compliance audits are already operating with incomplete data.&lt;/p&gt;
&lt;p&gt;Today, we&amp;rsquo;re excited to announce a new pre-built policy pack created in partnership with AWS: &lt;strong&gt;AWS Organizations Tag Policies&lt;/strong&gt;. This pack validates your infrastructure as code against tag policies configured in AWS Organizations, blocking deployments when required tags are missing and shifting tag governance left into your development workflow. Define your tag requirements once in AWS Organizations and enforce them consistently across all your Pulumi deployments.&lt;/p&gt;
&lt;h2 id="how-it-works"&gt;How it works&lt;/h2&gt;
&lt;p&gt;The new policy pack integrates directly with your AWS Organizations Tag Policies as the single source of truth. No separate policy configuration or custom code required. When you run &lt;code&gt;pulumi up&lt;/code&gt;, the pack retrieves your tag requirements from your AWS organization and validates that every resource has the required tags.&lt;/p&gt;
&lt;p&gt;Start by enabling the pack in advisory mode to surface tagging violations in Pulumi Cloud&amp;rsquo;s &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-findings/"&gt;Policy Findings&lt;/a&gt; hub without blocking deployments. This collaborative workspace allows your team to triage, prioritize, and systematically remediate missing tags. Once your infrastructure is compliant, switch to mandatory mode to prevent future non-compliant deployments.&lt;/p&gt;
&lt;h2 id="getting-started"&gt;Getting started&lt;/h2&gt;
&lt;p&gt;The pack works with both AWS Classic and AWS Native Pulumi providers, covering the full range of taggable AWS resources. To get started:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Configure tag policies&lt;/strong&gt; in AWS Organizations following the &lt;a href="https://docs.aws.amazon.com/organizations/latest/userguide/enforce-required-tag-keys-iac.html"&gt;AWS documentation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Grant required permissions&lt;/strong&gt; by adding the &lt;code&gt;resourcegroupstaggingapi:ListRequiredTags&lt;/code&gt; permission to the IAM role or user that runs your Pulumi deployments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enable the pack in Pulumi Cloud&lt;/strong&gt;:
&lt;ol&gt;
&lt;li&gt;From within your organization, navigate to the &lt;strong&gt;Policies&lt;/strong&gt; tab&lt;/li&gt;
&lt;li&gt;Under Policy Packs, select the &lt;strong&gt;Available&lt;/strong&gt; tab&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;AWS Organizations Tag Policies&lt;/strong&gt; and select &lt;strong&gt;Add to organization&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;From the Organizations tab, apply the policy to a Policy Group&lt;/li&gt;
&lt;/ol&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure enforcement level&lt;/strong&gt;: Set to advisory for warnings or mandatory to block non-compliant deployments.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Within minutes, every Pulumi deployment in your organization will validate tag compliance, ensuring that no resources are created without required tags.&lt;/p&gt;
&lt;h2 id="try-it-today"&gt;Try it today&lt;/h2&gt;
&lt;p&gt;The AWS Organizations Tag Policies policy pack is now available to all Pulumi Team and Enterprise customers.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/integrations/aws-organizations-tag-policies/"&gt;Get started with the integration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/organizations/latest/userguide/enforce-required-tag-keys-iac.html"&gt;Learn about enforcing tag policies with AWS Organizations Tag Policies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; if you&amp;rsquo;re new to Pulumi&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We&amp;rsquo;re excited to partner with AWS on this capability and help organizations proactively enforce tag governance. Give it a try and let us know what you think!&lt;/p&gt;</description><author>Alejandro Cotroneo</author><category>aws</category><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>governance</category><category>compliance</category></item><item><title>Announcing the Next Generation of Pulumi Policies: AI-Accelerated Governance for the Cloud</title><link>https://www.pulumi.com/blog/policy-next-gen/</link><pubDate>Wed, 05 Nov 2025 00:05:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-next-gen/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-next-gen/index.png" /&gt;
&lt;p&gt;The era of AI-accelerated development has created a paradox: the faster developers move, the bigger the governance challenge becomes. For years, security and platform teams have worked to &amp;ldquo;shift left,&amp;rdquo; but the tools available have been incomplete. Most focus on detection, which is necessary but not sufficient. They identify thousands of policy violations across an organization&amp;rsquo;s infrastructure but leave teams with an overwhelming backlog and no scalable way to remediate it. This creates a persistent gap between finding a problem and fixing it. The result is an impossible choice between development velocity and organizational control, forcing leadership to slow down innovation to manage risk.&lt;/p&gt;
&lt;p&gt;Today, we end that compromise.&lt;/p&gt;
&lt;p&gt;We are thrilled to announce the next generation of Pulumi Policies, a comprehensive governance solution that moves beyond detection to deliver AI-powered remediation at scale. We’re introducing a new lifecycle to secure your cloud: first, &lt;strong&gt;Get Clean&lt;/strong&gt; by using AI to fix your existing policy violations. Second, &lt;strong&gt;Stay Clean&lt;/strong&gt; by using policy as a universal guardrail that makes AI-driven development not just fast, but fundamentally safe. These are not strictly sequential steps; you can begin enforcing &amp;ldquo;Stay Clean&amp;rdquo; policies for all new infrastructure while you simultaneously work on the &amp;ldquo;Get Clean&amp;rdquo; process for your existing footprint.&lt;/p&gt;
&lt;p&gt;Watch our Launch Video:&lt;/p&gt;
&lt;div style="position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;"&gt;
&lt;iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen" loading="eager" referrerpolicy="strict-origin-when-cross-origin" src="https://www.youtube.com/embed/mwcrOTEf1EQ?rel=0?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0" style="position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;" title="YouTube video"&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;h2 id="part-1-get-clean---from-thousands-of-issues-to-a-compliant-state"&gt;Part 1: Get Clean - From Thousands of Issues to a Compliant State&lt;/h2&gt;
&lt;p&gt;The first step to a secure cloud is tackling the mountain of existing misconfigurations spread across your environments.&lt;/p&gt;
&lt;h3 id="first-gain-complete-visibility-with-the-new-policy-findings-hub"&gt;First, Gain Complete Visibility with the New Policy Findings Hub&lt;/h3&gt;
&lt;p&gt;To fix your issues, you first need to see them clearly. We have introduced a powerful &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/policy-issue-management/"&gt;Policy Findings Hub&lt;/a&gt;&lt;/strong&gt; designed to give every stakeholder the exact view they need.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Overview Tab:&lt;/strong&gt; A high-level dashboard with compliance scores for leadership to track trends and measure your organization&amp;rsquo;s posture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Compliance Tab:&lt;/strong&gt; A control-centric view for auditors and infosec teams, grouping findings by policy (e.g., CIS, NIST) to simplify evidence gathering and prove compliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Issues Tab:&lt;/strong&gt; A collaborative workspace for platform and development teams to triage, assign, prioritize, and track the remediation of every policy issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This hub is powered by our flexible audit capabilities. With &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/policy-audit-scans-for-stacks/"&gt;Audit Scans for IaC Stacks&lt;/a&gt;&lt;/strong&gt;, you can get an instant compliance baseline on all your existing Pulumi-managed infrastructure without blocking developers or re-deploying thousands of stacks. This is combined with discovery scans of your cloud accounts to give you a single, unified view of every resource, whether managed by Pulumi or not.&lt;/p&gt;
&lt;h3 id="the-solution-to-remediation-at-scale-ai-powered-fixes-with-pulumi-neo"&gt;The Solution to Remediation at Scale: AI-Powered Fixes with Pulumi Neo&lt;/h3&gt;
&lt;p&gt;Visibility creates a new problem: an overwhelming backlog. Manually fixing thousands of issues is an impossible task.&lt;/p&gt;
&lt;p&gt;This is where Pulumi Neo provides a powerful solution.&lt;/p&gt;
&lt;p&gt;Pulumi Neo, our AI platform engineer, is now integrated directly into the Policy Findings hub to automate the most difficult part of the process: the fix itself. From the Issues tab, your teams can now select a group of policy issues, assign them to Neo, and trigger a remediation flow.&lt;/p&gt;
&lt;p&gt;Neo is smart. It will:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Analyze the non-compliant resources and the policies they are violating.&lt;/li&gt;
&lt;li&gt;Understand the required configuration to make them compliant.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Generate a pull request with the exact code changes needed to fix the issues.&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Most powerfully, for an unmanaged resource discovered via a cloud scan, Neo will generate the code to &lt;strong&gt;import the resource into a Pulumi stack and apply the fix.&lt;/strong&gt; This &amp;ldquo;Import and Fix&amp;rdquo; workflow transforms unmanaged infrastructure into governed, compliant code, turning a task that could take a developer hours into a simple review-and-merge process. Your teams can finally burn down their issue backlog and achieve a state of continuous compliance.&lt;/p&gt;
&lt;h2 id="part-2-stay-clean---the-universal-guardrail-for-humans-and-ai"&gt;Part 2: Stay Clean - The Universal Guardrail for Humans and AI&lt;/h2&gt;
&lt;p&gt;Once you begin cleaning your environment, the next challenge is to &lt;em&gt;stay&lt;/em&gt; clean. As AI accelerates infrastructure creation, you need robust guardrails to ensure it doesn&amp;rsquo;t also accelerate the creation of security risks.&lt;/p&gt;
&lt;p&gt;The answer is &lt;strong&gt;Policy as &lt;em&gt;Real&lt;/em&gt; Code.&lt;/strong&gt; Pulumi Policies uses general-purpose languages like TypeScript and Python to create sophisticated guardrails that govern every change. To help you establish these controls immediately, we are launching a new suite of pre-built compliance packs authored and maintained by Pulumi experts.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th style="text-align: center"&gt;AWS&lt;/th&gt;
&lt;th style="text-align: center"&gt;Azure&lt;/th&gt;
&lt;th style="text-align: center"&gt;Google Cloud&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CIS Controls v8.1&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;PCI DSS v4.0&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;HITRUST CSF v11.5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Pulumi Best Practices&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;These policies act as a universal guardrail for your entire organization by blocking non-compliant changes during &lt;code&gt;pulumi up&lt;/code&gt;, before they are ever created. Learn more about our &lt;a href="https://www.pulumi.com/blog/policy-packs-cis-nist-pci/"&gt;compliance packs&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;And now, you can even use &lt;strong&gt;Neo to author new policies&lt;/strong&gt;. You can ask Neo in plain English to &amp;ldquo;create a policy that prevents overly permissive IAM roles,&amp;rdquo; and it will generate the code for you. This creates a powerful, dynamic governance system where AI can help you build the very rules that then govern its own actions. If you then ask Neo to create an admin role, the deployment will be blocked by the policy it just helped write. This is how we make AI safe to go fast.&lt;/p&gt;
&lt;h2 id="a-new-era-of-collaboration"&gt;A New Era of Collaboration&lt;/h2&gt;
&lt;p&gt;This &amp;ldquo;Get Clean, Stay Clean&amp;rdquo; lifecycle transforms how teams work together:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Platform Teams&lt;/strong&gt; lead prevention by building real-code guardrails, proving their value with measurable compliance scores.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Teams&lt;/strong&gt; drive the &amp;ldquo;Get Clean&amp;rdquo; process with continuous, non-blocking audit scans and use the Findings hub to manage compliance without slowing development.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="governance-that-accelerates-you"&gt;Governance That Accelerates You&lt;/h2&gt;
&lt;p&gt;The age of AI-driven development demands AI-powered governance. With this new generation of Pulumi Policies, we are providing the essential infrastructure for platform engineering teams to not just survive, but thrive. You can finally build preventative guardrails that developers love, secure your cloud at scale, and transform governance from a blocker into a business accelerator. Learn more about &lt;a href="https://www.pulumi.com/product/insights-governance/"&gt;Pulumi Insights &amp;amp; Governance capabilities&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This powerful new experience is available today. Navigate to the &lt;strong&gt;Policies&lt;/strong&gt; and &lt;strong&gt;Policy Findings&lt;/strong&gt; tab in Pulumi Cloud to explore your new governance capabilities and meet the future of platform engineering.&lt;/p&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi Policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Ready to try these features?&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and start a Neo task&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;Read the Get Started guide&lt;/a&gt; to set up and apply a policy group to stacks and clouds.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback on the new features&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For complete documentation, visit our &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policies documentation&lt;/a&gt;.&lt;/p&gt;</description><author>Craig Symonds</author><author>Tyler D</author><author>Arun Loganathan</author><category>policy-as-code</category><category>features</category><category>compliance</category><category>governance</category><category>pulumi-neo</category><category>ai</category><category>platform-engineering</category></item><item><title>New Audit Policy Scans for Pulumi Stacks</title><link>https://www.pulumi.com/blog/policy-audit-scans-for-stacks/</link><pubDate>Wed, 05 Nov 2025 00:04:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-audit-scans-for-stacks/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-audit-scans-for-stacks/index.png" /&gt;
&lt;p&gt;&lt;strong&gt;Audit Policy Scans for Pulumi Stacks&lt;/strong&gt; is part of the next generation of Pulumi Policies. This capability uses policies to run compliance checks against the last successful deployment state of your stacks, providing continuous compliance monitoring without impacting your existing CI/CD workflows.&lt;/p&gt;
&lt;p&gt;Until now, Pulumi’s preventative policies have served as a critical &amp;ldquo;shift-left&amp;rdquo; gate, blocking non-compliant changes during &lt;code&gt;pulumi up&lt;/code&gt;. While essential, this created challenges for organizations wanting to roll out new governance across thousands of existing stacks. This new evaluation mode solves that problem, giving you a complete and continuous view of your IaC compliance posture without the friction.&lt;/p&gt;
&lt;h2 id="a-complete-audit-story-cloud-accounts-and-iac-stacks"&gt;A Complete Audit Story: Cloud Accounts and IaC Stacks&lt;/h2&gt;
&lt;p&gt;Pulumi&amp;rsquo;s audit philosophy is to provide complete visibility across your entire cloud footprint. We achieve this through two complementary audit modes:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Audit Scans for Cloud Accounts (Existing):&lt;/strong&gt; This capability scans your live cloud environments (like an AWS account or Azure subscription). Its primary purpose is to give you a holistic view of your security posture by discovering &lt;em&gt;all&lt;/em&gt; resources, including those not managed by Pulumi, and detecting configuration drift. This is how you find unmanaged, legacy, or manually-created resources that violate your policies.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Audit Scans for Pulumi Stacks (New):&lt;/strong&gt; The feature extends this audit power to the source of truth for your managed infrastructure: your Pulumi stacks. It evaluates the &lt;em&gt;last successfully deployed state&lt;/em&gt; of your IaC. This allows you to get an instant compliance baseline of all your managed infrastructure without having to redeploy anything, making it perfect for frictionless policy rollouts at scale.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Together, these two audit modes give you a comprehensive picture of your entire cloud estate, all feeding into one unified &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/policy-issue-management/"&gt;Policy Findings hub&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="key-scenarios-for-audit-scans-for-stacks"&gt;Key Scenarios for Audit Scans for Stacks&lt;/h2&gt;
&lt;p&gt;This new evaluation mode for IaC stacks is designed to unlock policy adoption at scale and accelerate developer velocity. Key use cases include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Gain an instant compliance overview across all existing stacks:&lt;/strong&gt; Apply policies centrally and get immediate visibility into your compliance posture without requiring redeployment of every stack.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Accelerate policy rollouts:&lt;/strong&gt; By decoupling policy evaluation from the critical deployment path, deployments become faster and developers are unblocked. Teams still get immediate feedback on the compliance of the deployed infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ensure continuous compliance:&lt;/strong&gt; Evaluation is automatically triggered whenever policy configurations change. This ensures the &lt;em&gt;latest policies&lt;/em&gt; are always evaluated against the &lt;em&gt;latest deployed infrastructure&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="how-it-works"&gt;How It Works&lt;/h2&gt;
&lt;p&gt;This new mechanism runs against the last known successfully deployed state of your IaC Stacks as recorded by Pulumi Cloud.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Evaluation is triggered automatically&lt;/strong&gt; after a successful &lt;code&gt;pulumi up&lt;/code&gt; or when a policy pack attached to the stack is updated.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Results are unified&lt;/strong&gt; into the same &lt;strong&gt;Policy Findings hub&lt;/strong&gt; you use today, giving you a single pane of glass for all preventative and audit policy findings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="how-to-get-started"&gt;How to Get Started&lt;/h2&gt;
&lt;p&gt;You can enable audit scans for your IaC stacks by adding them to an &lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/policy-groups/#audit-policy-groups"&gt;Audit Policy Group&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Navigate to the &lt;strong&gt;Policies&lt;/strong&gt; tab in the left navigation bar of the Pulumi Cloud console.&lt;/li&gt;
&lt;li&gt;Create a new &lt;strong&gt;Audit Policy Group&lt;/strong&gt; or select an existing one.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Pulumi Stacks&lt;/strong&gt; and add the specific stacks you want to monitor.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Add Policy Packs&lt;/strong&gt; to the group.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Save the policy group&lt;/strong&gt;. That&amp;rsquo;s it!&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="my-4"&gt;
&lt;video class="flex outline-none rounded-lg w-full" title="Setting up Stack Audit Policy"
autoplay muted playsinline
loop &gt;
&lt;source src="stack-audit-policy.mp4" /&gt;
&lt;/video&gt;
&lt;/div&gt;
&lt;p&gt;The next time any of the selected stacks completes a &lt;code&gt;pulumi up&lt;/code&gt;, a post-deployment evaluation will be automatically triggered, and the results will populate in the Policy Findings hub.&lt;/p&gt;
&lt;div class="note note-info"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.21047dcd83825f0caafb78a6fd28628a694219e6b6824f6b3e24ee3147bac331.svg#p-info-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;Audit policy scans consume workflow minutes from your Pulumi Cloud plan. Each scan counts toward your monthly quota based on the complexity and number of resources evaluated. See pricing documentation for details.&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="a-complete-governance-picture"&gt;A Complete Governance Picture&lt;/h2&gt;
&lt;p&gt;With the addition of post-deployment evaluation for IaC stacks, you now have a complete, 360-degree view of your cloud environment. You can use audit scans for cloud accounts to get a handle on your entire live footprint, and use audit scans for stacks to easily assess your IaC-managed footprint without adding friction to your development process.&lt;/p&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi Policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Ready to try these features?&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and start a Neo task&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;Read the Get Started guide&lt;/a&gt; to continuously scan resources and identify violations&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback on the new features&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For complete documentation, visit our &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policies documentation&lt;/a&gt;.&lt;/p&gt;</description><author>Levi Blackstone</author><author>Arun Loganathan</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>audit-policies</category><category>compliance</category><category>governance</category></item><item><title>Policy Findings Hub: Move From Alert Fatigue to Action</title><link>https://www.pulumi.com/blog/policy-issue-management/</link><pubDate>Wed, 05 Nov 2025 00:03:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-issue-management/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-issue-management/index.png" /&gt;
&lt;p&gt;For platform and security teams, enabling robust cloud scanning often creates a new problem: an unmanageable firehose of policy alerts. Identifying a violation is only the first step. Without a system to manage the lifecycle of these findings, teams are quickly overwhelmed, leading to prioritization paralysis and a perpetually growing backlog.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/policy-findings/"&gt;Policy Findings&lt;/a&gt;&lt;/strong&gt; hub in Pulumi Cloud is the solution to this alert fatigue. It&amp;rsquo;s a purpose-built, collaborative workspace that turns a noisy list of violations into organized, actionable tasks. The hub brings clarity and structure to the compliance process, guiding teams from initial discovery to a verified fix.&lt;/p&gt;
&lt;h2 id="from-raw-data-to-actionable-insights"&gt;From Raw Data to Actionable Insights&lt;/h2&gt;
&lt;p&gt;The Policy Findings hub is designed with distinct views for every stakeholder involved in the governance lifecycle.&lt;/p&gt;
&lt;h3 id="1-the-overview-tab-a-dashboard-for-leaders"&gt;1. The Overview Tab: A Dashboard for Leaders&lt;/h3&gt;
&lt;p&gt;For a platform lead or security manager, the goal is to understand the big picture. The Overview tab provides a high-level dashboard of your organization&amp;rsquo;s compliance health, answering key questions at a glance:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What is our overall resource compliance score?&lt;/li&gt;
&lt;li&gt;Are we trending in the right direction?&lt;/li&gt;
&lt;li&gt;Which parts of our cloud infrastructure (stacks, accounts, etc.) carry the most risk?&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This view helps leadership track progress and make data-driven decisions about where to focus engineering efforts.&lt;/p&gt;
&lt;h3 id="2-the-compliance-tab-the-auditor-and-infosec-workspace"&gt;2. The Compliance Tab: The Auditor and Infosec Workspace&lt;/h3&gt;
&lt;p&gt;For the infosec members and auditors, context is everything. Simply listing thousands of violations is not helpful. The Compliance tab provides a policy-centric view, grouping all findings by the specific control they violated (e.g., a specific rule within CIS or NIST).&lt;/p&gt;
&lt;p&gt;This is crucial when preparing for an audit or assessing adherence to a specific security framework, as it allows you to &lt;a href="https://www.pulumi.com/blog/policy-packs-cis-nist-pci/#more-than-just-detection-the-complete-governance-lifecycle"&gt;see exactly where you are compliant and where you have gaps&lt;/a&gt;, control by control.&lt;/p&gt;
&lt;h3 id="3-the-issues-tab-the-teams-daily-workspace"&gt;3. The Issues Tab: The Team&amp;rsquo;s Daily Workspace&lt;/h3&gt;
&lt;p&gt;This is the space where insight is turned into action. The Issues tab is a collaborative triage board designed for the day-to-day workflow of platform and development teams. It provides the full toolset needed to manage the lifecycle of an issue from start to finish:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Triage and Prioritize:&lt;/strong&gt; Filter issues by severity, resource type, or policy to focus on what matters most. Set a priority level from P0 (critical) to P4 (low).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Assign Ownership:&lt;/strong&gt; Assign issues to specific team members to ensure clear ownership and accountability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Manage Lifecycle:&lt;/strong&gt; Mark an issue as &amp;ldquo;Ignored&amp;rdquo; with a justification. This is a critical workflow for acknowledging intentional exceptions, which cleans up your dashboard and allows the team to focus on legitimate issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And for the most critical part of the workflow — the fix itself — we&amp;rsquo;ve integrated our AI agent, &lt;strong&gt;&lt;a href="https://www.pulumi.com/product/neo/#video"&gt;Pulumi Neo&lt;/a&gt;&lt;/strong&gt;, directly into this view.&lt;/p&gt;
&lt;p&gt;After selecting one or more issues, your team can assign the task to Neo. It will analyze the violations and automatically generate a pull request with the necessary code changes. For unmanaged resources, Neo will even generate the code to import them into Pulumi and apply the fix. This turns a complex manual task into a simple review-and-merge process, allowing your team to finally burn down the backlog.&lt;/p&gt;
&lt;div class="my-4"&gt;
&lt;video class="flex outline-none rounded-lg w-full" title="Managing policy findings in Pulumi Cloud"
controls
loop &gt;
&lt;source src="findingsclipblog.mp4" /&gt;
&lt;/video&gt;
&lt;/div&gt;
&lt;h2 id="turning-alerts-into-action"&gt;Turning Alerts into Action&lt;/h2&gt;
&lt;p&gt;Effective governance goes beyond identifying violations. It requires a structured system that turns every finding into a clear and trackable path to resolution. The new Policy Findings hub provides that end-to-end workflow, from visibility to accountability to automated remediation.&lt;/p&gt;
&lt;p&gt;By organizing policy data into meaningful views and integrating Pulumi Neo directly into the issue management process, teams can move past alert fatigue and focus on what matters most: fixing problems quickly and maintaining continuous compliance.&lt;/p&gt;
&lt;p&gt;This new experience is now available. Navigate to the &lt;strong&gt;Policies &amp;gt; Findings&lt;/strong&gt; tab in the Pulumi Cloud to explore your new compliance dashboard and start turning alerts into action.&lt;/p&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi Policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Ready to try these features?&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and start a Neo task&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;Read the Get Started guide&lt;/a&gt; to manage compliance across your cloud infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback on the new features&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For complete documentation, visit our &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policies documentation&lt;/a&gt;.&lt;/p&gt;</description><author>Alejandro Cotroneo</author><author>Arun Loganathan</author><category>pulumi-cloud</category><category>policy-as-code</category><category>audit-policies</category><category>compliance</category><category>governance</category><category>pulumi-neo</category><category>infosec</category></item><item><title>New Compliance Packs for CIS, NIST, and PCI DSS</title><link>https://www.pulumi.com/blog/policy-packs-cis-nist-pci/</link><pubDate>Wed, 05 Nov 2025 00:02:00 +0000</pubDate><guid>https://www.pulumi.com/blog/policy-packs-cis-nist-pci/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/policy-packs-cis-nist-pci/index.png" /&gt;
&lt;p&gt;Achieving compliance with industry standards such as &lt;strong&gt;CIS, NIST&lt;/strong&gt;, or &lt;strong&gt;PCI DSS&lt;/strong&gt; is a foundational step for every organization. Yet for many teams, it&amp;rsquo;s often a manual, months-long process that involves interpreting controls, authoring custom policies, and validating configurations across multiple clouds. These challenges often slow progress toward a known and secure cloud state.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;re changing that. To simplify this journey, Pulumi launched a new suite of &lt;strong&gt;pre-built compliance policy packs&lt;/strong&gt; for &lt;a href="https://www.pulumi.com/docs/insights/policy/policy-packs/pre-built-packs/#available-policy-packs"&gt;CIS Controls v8.1, NIST SP 800-53 Rev. 5, and PCI DSS v4.0&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;These packs are your accelerator for the &amp;ldquo;&lt;strong&gt;Get Clean&lt;/strong&gt;&amp;rdquo; journey, allowing you to enforce critical security and compliance baselines across your cloud infrastructure &lt;strong&gt;in minutes, not months&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="more-than-just-detection-the-complete-governance-lifecycle"&gt;More Than Just Detection: The Complete Governance Lifecycle&lt;/h2&gt;
&lt;p&gt;Traditional security tools are reactive, scanning for problems &lt;em&gt;after&lt;/em&gt; resources have been deployed. With Pulumi, these new compliance packs are the engine for an end-to-end governance lifecycle that integrates directly into your cloud operations.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Audit for Full Coverage:&lt;/strong&gt; Run these packs in audit mode to scan your entire cloud estate, including resources managed by Pulumi and those created through other means. This gives you an instant, comprehensive view of your current compliance posture.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Triage and Remediate:&lt;/strong&gt; When a pack finds a violation, the finding appears in the new &lt;strong&gt;&lt;a href="https://www.pulumi.com/blog/policy-issue-management/"&gt;Policy Findings hub&lt;/a&gt;&lt;/strong&gt;. From there, your team can triage, assign, and track the issue through its entire lifecycle. And with our new AI-powered capabilities, you can assign the issue to &lt;strong&gt;Pulumi Neo&lt;/strong&gt; to automatically generate a pull request with the fix.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Prevent Non-Compliance:&lt;/strong&gt; Once your environment is clean, you use these same packs as preventative guardrails. By running them during &lt;code&gt;pulumi up&lt;/code&gt;, you block non-compliant resources &lt;em&gt;before they are ever created&lt;/em&gt;, ensuring you &amp;ldquo;Stay Clean.&amp;rdquo;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This tri-modal capability—Audit, Remediate, and Prevent—is uniquely powerful, allowing you to fix existing issues while stopping new ones from being introduced.&lt;/p&gt;
&lt;h2 id="new-and-expanded-compliance-packs"&gt;New and Expanded Compliance Packs&lt;/h2&gt;
&lt;p&gt;Our new policy packs provide extensive, out-of-the-box coverage for some of the most widely adopted security frameworks. They are authored and maintained by Pulumi experts and join our existing library to provide a comprehensive toolkit for cloud governance.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Framework&lt;/th&gt;
&lt;th style="text-align: center"&gt;AWS&lt;/th&gt;
&lt;th style="text-align: center"&gt;Azure&lt;/th&gt;
&lt;th style="text-align: center"&gt;Google Cloud&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;CIS Controls v8.1&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;NIST SP 800-53 Rev. 5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;PCI DSS v4.0&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;HITRUST CSF v11.5&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Pulumi Best Practices&lt;/strong&gt;&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;td style="text-align: center"&gt;✅&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="benefits-of-pre-built-packs"&gt;Benefits of Pre-Built Packs&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Accelerate Compliance:&lt;/strong&gt; Implement comprehensive governance controls in minutes without authoring hundreds of policies from scratch.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Leverage Expert Knowledge:&lt;/strong&gt; Packs are authored and maintained by Pulumi, incorporating deep expertise in cloud and the nuances of each framework.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Codify Controls for Audits:&lt;/strong&gt; Demonstrate to auditors that specific compliance controls are consistently enforced through code, providing a clear evidence trail.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduce Risk Proactively:&lt;/strong&gt; Catch common security risks and compliance violations before deployment, drastically reducing your organization&amp;rsquo;s exposure.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="get-started-today"&gt;Get Started Today&lt;/h2&gt;
&lt;p&gt;These policy packs are available now and are the perfect way to begin your governance journey with Pulumi.&lt;/p&gt;
&lt;p&gt;To get started, head to the &lt;strong&gt;Policies&lt;/strong&gt; page in your Pulumi Cloud organization and click on the &lt;strong&gt;All&lt;/strong&gt; tab to find these new packs. Add them to an &lt;strong&gt;Audit Policy Group&lt;/strong&gt; and run a scan. Within minutes, you&amp;rsquo;ll see a complete picture of your compliance posture in the &lt;strong&gt;Policy Findings hub&lt;/strong&gt;, ready for triage and remediation.&lt;/p&gt;
&lt;p&gt;Need a compliance pack for a standard that isn&amp;rsquo;t listed here? Please let us know by raising a request on our &lt;a href="https://github.com/pulumi/pulumi-cloud-requests"&gt;GitHub repository&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="try-pulumi-policies"&gt;Try Pulumi Policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;New to Pulumi? Start your governance journey today.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://app.pulumi.com/signup"&gt;Sign up for Pulumi Cloud&lt;/a&gt; and start a compliance task with Neo&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pulumi.com/docs/insights/policy/get-started/"&gt;Read the Get Started guide&lt;/a&gt; to apply and manage policies across your cloud infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://slack.pulumi.com/"&gt;Join the Community Slack&lt;/a&gt; to share feedback on the new features&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For complete documentation, visit our &lt;a href="https://www.pulumi.com/docs/insights/policy/"&gt;Policies documentation&lt;/a&gt;.&lt;/p&gt;</description><author>Luke Ward</author><author>Dan Biwer</author><category>pulumi-cloud</category><category>policy-as-code</category><category>crossguard</category><category>features</category><category>compliance</category><category>governance</category><category>security</category></item><item><title>How to Implement Robust Security Guardrails Using Policy as Code</title><link>https://www.pulumi.com/blog/deployment-guardrails-with-policy-as-code/</link><pubDate>Tue, 30 Sep 2025 00:00:00 +0000</pubDate><guid>https://www.pulumi.com/blog/deployment-guardrails-with-policy-as-code/</guid><description>
&lt;img src="https://www.pulumi.com/images/generated/blog/deployment-guardrails-with-policy-as-code/index.png" /&gt;
&lt;p&gt;Welcome to the third post in our &lt;strong&gt;IDP Best Practices&lt;/strong&gt; series, where we explore how to implement &lt;strong&gt;policy as code&lt;/strong&gt; with &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard"&gt;Pulumi CrossGuard&lt;/a&gt; to create deployment guardrails that make self-service infrastructure both powerful and safe.&lt;/p&gt;
&lt;p&gt;Platform engineering presents a fundamental tension: we want to enable developer velocity while maintaining security and compliance. Every platform team faces the same question: how do you give teams the freedom to deploy infrastructure quickly without compromising on safety, security, or organizational standards? The answer isn&amp;rsquo;t to choose between speed and safety, but rather to embrace &lt;strong&gt;automated guardrails&lt;/strong&gt; powered by policy as code that make both possible simultaneously.&lt;/p&gt;
&lt;div class="note note-tip"&gt;
&lt;div class="icon-and-line"&gt;
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--fill" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.21047dcd83825f0caafb78a6fd28628a694219e6b6824f6b3e24ee3147bac331.svg#p-lightbulb-fill"/&gt;&lt;/svg&gt;
&lt;div class="line"&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div class="content"&gt;&lt;strong&gt;Want hands-on experience?&lt;/strong&gt; Access the &lt;a href="https://github.com/pulumi/workshops/tree/main/idp-component-policies"&gt;complete demo code&lt;/a&gt; and &lt;a href="https://github.com/pulumi/workshops/tree/main/idp-component-policies/demo-policies"&gt;policy examples&lt;/a&gt; from this workshop.&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="the-platform-engineering-challenge-speed-vs-safety"&gt;The Platform Engineering Challenge: Speed vs. Safety&lt;/h2&gt;
&lt;p&gt;Let me tell you a story that perfectly captures the platform engineering dilemma. Statsig, a fast-growing feature flag platform processing an incredible 2 trillion events daily, had one infrastructure engineer named Jason who handled all infrastructure requests. Everything worked smoothly until Jason went on parental leave. Suddenly, the entire engineering organization ground to a halt. Infrastructure requests piled up, deployments slowed to a crawl, and the team faced a stark realization: their entire infrastructure capability depended on a single person.&lt;/p&gt;
&lt;p&gt;This crisis forced them to confront a fundamental question that every growing engineering team eventually faces: How do you enable self-service infrastructure without sacrificing security, compliance, or operational stability? The answer wasn&amp;rsquo;t to hire more Jasons or to lock down infrastructure even tighter. Instead, they discovered that deployment guardrails with policy as code could transform their infrastructure conversation from &amp;ldquo;talk to the infrastructure person&amp;rdquo; to &amp;ldquo;ship with confidence, knowing guardrails will catch any issues.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Think of it like building a system of roads with guardrails. When you create well-designed infrastructure components with proper safety barriers, teams can drive fast and confidently, knowing they&amp;rsquo;re protected from going off the cliff. The guardrails don&amp;rsquo;t slow them down; they enable speed by removing fear.&lt;/p&gt;
&lt;h2 id="understanding-platform-engineering-layers"&gt;Understanding Platform Engineering Layers&lt;/h2&gt;
&lt;p&gt;Before we dive into implementing guardrails, we need to understand the architecture of a modern platform and where policies fit within it. Think of your platform as having three distinct layers, each with different security and access requirements.&lt;/p&gt;
&lt;p&gt;At the foundation, you have your &lt;strong&gt;Layer 1: Foundational Infrastructure&lt;/strong&gt;, which includes security controls, shared networking, and identity management systems like OIDC and IAM. Platform teams typically manage this layer with strict access controls because it forms the security backbone of your entire infrastructure.&lt;/p&gt;
&lt;p&gt;Building on that foundation is &lt;strong&gt;Layer 2: Shared Infrastructure&lt;/strong&gt;, which encompasses VPCs, compute platforms, and load balancers. These are standardized components that teams can use but with some room for customization based on specific needs.&lt;/p&gt;
&lt;p&gt;The most dynamic layer is &lt;strong&gt;Layer 3: The Workloads Layer&lt;/strong&gt;, where deployable artifacts, pipelines, and operability tools live. This is where the rubber meets the road, where most self-service activity happens and, consequently, where guardrails become absolutely critical. Developers need maximum freedom at this layer to innovate and ship quickly, but this freedom also introduces the most risk. It&amp;rsquo;s precisely here that policy-driven guardrails prove their worth, enabling that freedom while automatically preventing dangerous configurations.&lt;/p&gt;
&lt;h2 id="what-are-deployment-guardrails"&gt;What Are Deployment Guardrails?&lt;/h2&gt;
&lt;p&gt;Deployment guardrails are automated policies that act as your infrastructure&amp;rsquo;s safety net. Rather than relying on manual reviews or hoping developers remember all the security requirements, guardrails automatically prevent misconfigurations before they reach production. They enforce security standards without human intervention, guide developers toward best practices through immediate feedback, and enable safe self-service by catching issues at the earliest possible moment.&lt;/p&gt;
&lt;p&gt;A helpful analogy is to think of guardrails like type checking in programming languages. Just as TypeScript doesn&amp;rsquo;t restrict your ability to write JavaScript but rather catches type errors before runtime, deployment guardrails don&amp;rsquo;t limit your infrastructure creativity. They simply ensure you&amp;rsquo;re following secure patterns and catch potentially dangerous configurations before they cause problems in production.&lt;/p&gt;
&lt;h2 id="introducing-pulumi-crossguard-policy-as-code"&gt;Introducing Pulumi CrossGuard: Policy as Code&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard"&gt;Pulumi CrossGuard&lt;/a&gt; is Pulumi&amp;rsquo;s policy as code framework that brings the same engineering rigor to compliance and security that you apply to your application code. Instead of maintaining policy documents in wikis or relying on manual reviews, you can write policies in familiar programming languages like &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/get-started#writing-policies-in-python"&gt;Python&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/get-started#writing-policies-in-typescript"&gt;TypeScript&lt;/a&gt;, or Go. These policies then enforce themselves across all your cloud resources and providers, running at different stages of the deployment lifecycle and integrating seamlessly with your CI/CD pipelines for automated enforcement.&lt;/p&gt;
&lt;h3 id="key-policy-types"&gt;Key Policy Types&lt;/h3&gt;
&lt;p&gt;CrossGuard supports two fundamental types of policies, each serving different validation needs:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#resource-validation"&gt;Resource Policies&lt;/a&gt;&lt;/strong&gt;: Validate individual resources&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;restrict_dangerous_ports&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;ResourceValidationArgs&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;ReportViolation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:lb/targetGroup:TargetGroup&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;port&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;port&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;dangerous_ports&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;22&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;23&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3389&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;port&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;dangerous_ports&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Dangerous port detected. Avoid using SSH, Telnet, or RDP ports.&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#stack-validation"&gt;Stack Policies&lt;/a&gt;&lt;/strong&gt;: Validate relationships across resources&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;validate_microservice_encryption&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;StackValidationArgs&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;ReportViolation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;microservice_components&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resources&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;custom:infrastructure:Microservice&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;microservice_components&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;elif&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:s3/bucket:Bucket&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;microservice_components&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;encryption&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;serverSideEncryptionConfiguration&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;encryption&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;S3 bucket must have encryption enabled when used with microservice components.&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="building-practical-guardrails-real-world-examples"&gt;Building Practical Guardrails: Real-World Examples&lt;/h2&gt;
&lt;p&gt;Let&amp;rsquo;s walk through building guardrails for a microservice platform, starting with the component from our &lt;a href="https://www.pulumi.com/blog/golden-paths-infrastructure-components-and-templates/"&gt;previous workshop&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id="example-1-port-security-policy"&gt;Example 1: Port Security Policy&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;: Developers might accidentally expose services on dangerous ports like SSH (22) or RDP (3389).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;: A policy that blocks dangerous port configurations.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;pulumi_policy&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;policy&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;restrict_dangerous_ports_validation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;&amp;#34;&amp;#34;Prevent services from running on dangerous ports.&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:lb/targetGroup:TargetGroup&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;port&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;port&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;dangerous_ports&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;22&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;23&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3389&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;5432&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3306&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="nb"&gt;str&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;port&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;dangerous_ports&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Port &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;port&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; is not allowed. This port is commonly used for &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;administrative services and should not be exposed via load balancer.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;restrict_dangerous_ports&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ResourceValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;restrict-dangerous-ports&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Prevent services from using dangerous ports&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;validate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;restrict_dangerous_ports_validation&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enforcement_level&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MANDATORY&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="example-2-resource-limits-policy"&gt;Example 2: Resource Limits Policy&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;: Teams might request oversized resources, leading to cost overruns.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;: A policy that enforces reasonable resource limits with advisory warnings.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;limit_memory_validation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;&amp;#34;&amp;#34;Limit memory allocation for microservices.&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;custom:infrastructure:Microservice&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Extract memory from component tags or properties&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;memory_str&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;memory&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;512Mi&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Parse memory value (assuming format like &amp;#34;2Gi&amp;#34;, &amp;#34;1024Mi&amp;#34;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;memory_str&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;endswith&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Gi&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;memory_gb&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;float&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;memory_str&lt;/span&gt;&lt;span class="p"&gt;[:&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;memory_gb&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Memory allocation of &lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;memory_str&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt; exceeds recommended limit of 1Gi &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;for microservices. Consider optimizing your application or &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;contact the platform team for exceptions.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;limit_memory&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ResourceValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;limit-microservice-memory&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Enforce reasonable memory limits for microservices&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;validate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;limit_memory_validation&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enforcement_level&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ADVISORY&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="example-3-cross-resource-security-policy"&gt;Example 3: Cross-Resource Security Policy&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Problem&lt;/strong&gt;: When microservices use S3 buckets, encryption should be mandatory.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;: A stack policy that validates encryption across related resources.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;microservice_s3_encryption_validation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;&amp;#34;&amp;#34;Ensure S3 buckets used with microservices have encryption enabled.&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;microservice_resources&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Collect relevant resources&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resources&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;custom:infrastructure:Microservice&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;microservice_resources&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;elif&lt;/span&gt; &lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:s3/bucket:Bucket&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;append&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;resource&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# If we have both microservices and S3 buckets, check encryption&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;microservice_resources&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;s3_buckets&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;sse_config&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;serverSideEncryptionConfiguration&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;sse_config&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;S3 bucket &amp;#39;&lt;/span&gt;&lt;span class="si"&gt;{&lt;/span&gt;&lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="si"&gt;}&lt;/span&gt;&lt;span class="s2"&gt;&amp;#39; must have server-side encryption &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="sa"&gt;f&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;enabled when used with microservice components.&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;microservice_s3_encryption&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;StackValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;microservice-s3-encryption&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Ensure S3 buckets used with microservices are encrypted&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;validate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;microservice_s3_encryption_validation&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enforcement_level&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;MANDATORY&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="policy-enforcement-models"&gt;Policy Enforcement Models&lt;/h2&gt;
&lt;p&gt;Pulumi CrossGuard supports multiple &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#enforcement-levels"&gt;enforcement models&lt;/a&gt; to fit different workflows, and understanding when to use each model is crucial for effective policy implementation.&lt;/p&gt;
&lt;h3 id="the-preventative-model"&gt;The Preventative Model&lt;/h3&gt;
&lt;p&gt;The most common approach is the preventative model, where policies run before resources are created. This gives you fast feedback and prevents bad deployments from ever reaching the cloud. When you run &lt;code&gt;pulumi preview&lt;/code&gt;, policies are evaluated immediately, and if violations are found during &lt;code&gt;pulumi up&lt;/code&gt;, the deployment is blocked. This model works particularly well for validating port configurations, resource limits, and other settings that you can check without needing to see the actual deployed resource.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Policies run automatically during preview and deployment&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;pulumi preview &lt;span class="c1"&gt;# Policies evaluated here&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;pulumi up &lt;span class="c1"&gt;# Policies block deployment if violations found&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="the-detective-model"&gt;The Detective Model&lt;/h3&gt;
&lt;p&gt;Sometimes you need to validate the actual cloud state, including auto-generated values like ARNs or IP addresses. That&amp;rsquo;s where the detective model comes in. These policies run after resources are created, making them perfect for compliance scanning and drift detection. While they can&amp;rsquo;t prevent initial deployment of non-compliant resources, they excel at catching configuration drift and validating properties that only exist after deployment.&lt;/p&gt;
&lt;h3 id="cicd-integration"&gt;CI/CD Integration&lt;/h3&gt;
&lt;p&gt;The third model integrates policies directly into your deployment pipeline. This ensures consistent enforcement across all teams and creates natural deployment gates. For example, you might configure &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/continuous-delivery/github-actions"&gt;GitHub Actions&lt;/a&gt; to run policy validation on every pull request, blocking merges if violations are found. This approach combines the best of both worlds: early feedback during development and guaranteed enforcement before production.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# GitHub Actions example&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;- &lt;span class="nt"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;Run Policy Validation&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;run&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="sd"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="sd"&gt; pulumi preview --policy-pack ./policies
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="sd"&gt; if [ $? -ne 0 ]; then
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="sd"&gt; echo &amp;#34;Policy violations found. Deployment blocked.&amp;#34;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="sd"&gt; exit 1
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="sd"&gt; fi&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="policy-remediation-beyond-detection"&gt;Policy Remediation: Beyond Detection&lt;/h2&gt;
&lt;p&gt;Modern policy frameworks don&amp;rsquo;t just detect violations; they can &lt;strong&gt;&lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#remediation-policies"&gt;automatically fix&lt;/a&gt;&lt;/strong&gt; them:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;auto_tag_resources&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;&amp;#34;&amp;#34;Automatically add required tags to resources.&amp;#34;&amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;resource_type&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;aws:s3/bucket:Bucket&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;tags&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;get&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{})&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Department&amp;#34;&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;tags&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Instead of just reporting, fix the issue&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="nb"&gt;hasattr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;tags&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Department&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Engineering&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;props&lt;/span&gt; &lt;span class="c1"&gt;# Return modified properties&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="kc"&gt;None&lt;/span&gt; &lt;span class="c1"&gt;# No changes needed&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;auto_tag_policy&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ResourceValidationPolicy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;auto-tag-resources&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Automatically add required tags&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;validate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;auto_tag_resources&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;enforcement_level&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;policy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;EnforcementLevel&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;REMEDIATE&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="server-side-policy-enforcement"&gt;Server-Side Policy Enforcement&lt;/h2&gt;
&lt;p&gt;For enterprise deployments, Pulumi provides &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/get-started#enforcing-a-policy-pack"&gt;server-side policy enforcement&lt;/a&gt; that ensures policies can&amp;rsquo;t be bypassed. The process starts by publishing your policies to your Pulumi organization with &lt;code&gt;pulumi policy publish ./my-policies&lt;/code&gt;. Once published, you can &lt;a href="https://www.pulumi.com/docs/iac/crossguard/configuration/#using-pulumi-cloud"&gt;create policy groups&lt;/a&gt; that combine multiple policies with specific enforcement levels, targeting particular stacks or environments while configuring exceptions for special cases. The beauty of this approach is that policies run automatically without requiring CLI flags, providing consistent governance across your entire organization without relying on developers to remember to include policy packs in their commands.&lt;/p&gt;
&lt;h2 id="compliance-ready-policies"&gt;Compliance-Ready Policies&lt;/h2&gt;
&lt;p&gt;While custom policies address your specific organizational needs, compliance requirements often follow industry standards. Pulumi provides hundreds of &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies"&gt;pre-built policies&lt;/a&gt; for common compliance frameworks:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-typescript" data-lang="typescript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;PolicyManager&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="kr"&gt;from&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;@pulumi/policy&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kr"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;policyManager&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="kr"&gt;from&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;@pulumi/compliance-ready-policies/policy-manager&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;new&lt;/span&gt; &lt;span class="nx"&gt;PolicyPack&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;aws-compliance-ready-policies-typescript&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;policies&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;...&lt;/span&gt;&lt;span class="nx"&gt;policyManager&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;selectPolicies&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;vendors&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;aws&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;services&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ec2&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;s3&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;severities&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;medium&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;high&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;critical&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;topics&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;encryption&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nx"&gt;frameworks&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;pcidss&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;},&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;mandatory&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;],&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;});&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This automatically includes policies for major compliance frameworks like &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies#frameworks"&gt;PCI DSS&lt;/a&gt; for payment card industry standards, &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies#frameworks"&gt;SOC 2&lt;/a&gt; for security and compliance controls, &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies#frameworks"&gt;ISO 27001&lt;/a&gt; for information security management, and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies#frameworks"&gt;CIS Benchmarks&lt;/a&gt; for security configuration standards.&lt;/p&gt;
&lt;div class="rounded-lg bg-violet-50 p-6 my-8"&gt;
&lt;p class="heading-4 m-0 mb-3 flex items-center gap-1.5"&gt;Add guardrails with policy as code&lt;/p&gt;
&lt;div class="body-base m-0 text-gray-950"&gt;Write policies in Python or TypeScript, enforce them across every deployment, and give teams self-service infrastructure that stays secure and compliant.&lt;/div&gt;
&lt;a href="https://www.pulumi.com/docs/insights/policy/" data-track="blog-body-cta" class="btn btn-primary mt-4"&gt;
Get started
&lt;svg xmlns="http://www.w3.org/2000/svg" class="ph-icon ph-icon--regular size-4" fill="currentColor" aria-hidden="true" focusable="false"&gt;&lt;use href="https://www.pulumi.com/icons/sprite.21047dcd83825f0caafb78a6fd28628a694219e6b6824f6b3e24ee3147bac331.svg#p-arrow-right-regular"/&gt;&lt;/svg&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;h2 id="best-practices-for-policy-implementation"&gt;Best Practices for Policy Implementation&lt;/h2&gt;
&lt;p&gt;After implementing policies at dozens of organizations, we&amp;rsquo;ve learned that successful policy adoption follows predictable patterns. The key is to adopt a product mindset: think of your policies as a product serving your development teams, not as bureaucratic rules imposed from above. Start small and iterate based on real feedback rather than trying to implement a comprehensive policy framework from day one.&lt;/p&gt;
&lt;h3 id="start-small-and-iterate"&gt;Start Small and Iterate&lt;/h3&gt;
&lt;p&gt;Begin with just two or three critical policies that address your most pressing risks. Use &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#enforcement-levels"&gt;advisory enforcement&lt;/a&gt; initially, which warns developers about violations but doesn&amp;rsquo;t block deployments. This gives your team time to understand and adapt to the policies. Only after gathering feedback and refining the policies should you graduate to mandatory enforcement.&lt;/p&gt;
&lt;h3 id="provide-clear-actionable-error-messages"&gt;Provide Clear, Actionable Error Messages&lt;/h3&gt;
&lt;p&gt;Nothing frustrates developers more than cryptic policy violations. Your error messages should explain not just what&amp;rsquo;s wrong, but how to fix it:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;good_error_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;violation_detected&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;report_violation&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;S3 bucket encryption is required for compliance. &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;Add serverSideEncryptionConfiguration to fix this. &amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;See: https://docs.company.com/s3-encryption&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="embrace-progressive-enforcement"&gt;Embrace Progressive Enforcement&lt;/h3&gt;
&lt;p&gt;Think of enforcement levels as a dial, not a switch. Start with &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#advisory"&gt;advisory&lt;/a&gt; mode to warn about issues, move to &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#mandatory"&gt;mandatory&lt;/a&gt; to block deployments, and eventually implement &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#remediation-policies"&gt;remediation&lt;/a&gt; to automatically fix common issues. This progression gives teams time to adapt while gradually raising the security bar.&lt;/p&gt;
&lt;h3 id="test-your-policies-thoroughly"&gt;Test Your Policies Thoroughly&lt;/h3&gt;
&lt;p&gt;Policies are code, and like any code, they need testing. Write unit tests for your policies to ensure they catch violations correctly and don&amp;rsquo;t produce false positives:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Test policies with unit tests&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;test_dangerous_port_policy&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;# Mock resource with port 22&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;args&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;create_mock_args&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;aws:lb/targetGroup:TargetGroup&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;port&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="mi"&gt;22&lt;/span&gt;&lt;span class="p"&gt;})&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;violations&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;run_policy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;restrict_dangerous_ports&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;args&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;assert&lt;/span&gt; &lt;span class="nb"&gt;len&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;violations&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;assert&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;dangerous port&amp;#34;&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;violations&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lower&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="document-escape-hatches"&gt;Document Escape Hatches&lt;/h3&gt;
&lt;p&gt;No matter how well-designed your policies are, there will always be edge cases. Rather than forcing teams to work around policies in dangerous ways, provide clear, documented escape hatches. Create processes for requesting exceptions, handling emergency exemptions, and appealing for policy changes. As one platform engineer put it, you need &amp;ldquo;guardrails outside the guardrails&amp;rdquo; because platform adoption will never be 100%, and that&amp;rsquo;s okay. This transparency builds trust and ensures policies remain effective enablers rather than bureaucratic obstacles to circumvent.&lt;/p&gt;
&lt;h2 id="real-world-success-statsigs-transformation"&gt;Real-World Success: Statsig&amp;rsquo;s Transformation&lt;/h2&gt;
&lt;p&gt;Remember Statsig&amp;rsquo;s infrastructure crisis when Jason went on parental leave? Let&amp;rsquo;s look at how they transformed their platform using the guardrails approach we&amp;rsquo;ve been discussing. After implementing policy-driven guardrails, their infrastructure story completely changed.&lt;/p&gt;
&lt;p&gt;As Tyrone Wong, Infrastructure Engineer at Statsig, explains: &amp;ldquo;We had a single infra owner. Parental leave forced us to build self-service, and that&amp;rsquo;s when everything clicked. Developers open a PR, Pulumi previews the change right in the PR, and CI blocks risky changes. That&amp;rsquo;s how you move fast safely. The magic was turning &amp;rsquo;talk to the infra person&amp;rsquo; into &amp;lsquo;ship with guardrails.&amp;rsquo;&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The results speak for themselves. Deployment times dropped from 1.5 weeks to mere minutes. The infrastructure ticket queue that once haunted their Slack channels disappeared entirely. Security actually improved through automated policy enforcement, eliminating the human error factor. Most importantly, developer satisfaction soared as teams gained the autonomy to ship infrastructure changes without friction or fear.&lt;/p&gt;
&lt;p&gt;When asked if developers were actually using the self-service platform, Tyrone&amp;rsquo;s response was telling: &amp;ldquo;Yeah, people are actually using it because there&amp;rsquo;s changes they wanted to get done. Previously it became this giant effort with lots of meetings, people being concerned, and Google docs about what the changes would be. Now people can just put together a PR, we have our discussions there, see if anything gets flagged, and move forward.&amp;rdquo;&lt;/p&gt;
&lt;h2 id="building-your-policy-strategy"&gt;Building Your Policy Strategy&lt;/h2&gt;
&lt;p&gt;Implementing deployment guardrails isn&amp;rsquo;t a big-bang transformation; it&amp;rsquo;s a journey that unfolds in phases. Based on patterns we&amp;rsquo;ve seen across successful implementations, the first week or two should focus on assessment. Start by understanding your current state, auditing existing infrastructure patterns to identify what teams are actually deploying. Look for common misconfigurations that have caused incidents or near-misses, and document your security and compliance requirements as specific, enforceable rules. Most importantly, survey your developers to understand their pain points with the current infrastructure process, as this assessment forms the foundation for policies that solve real problems rather than creating new ones.&lt;/p&gt;
&lt;p&gt;In weeks three and four, build your foundation by implementing three to five core policies that address your most critical risks. Set up &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/continuous-delivery"&gt;CI/CD integration&lt;/a&gt; so policies run automatically on every pull request, starting with advisory enforcement to gather feedback without blocking deployments. Create clear documentation and runbooks that explain not just what the policies do, but why they exist and how to work with them.&lt;/p&gt;
&lt;p&gt;By the second month, you&amp;rsquo;re ready to expand. Add &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies"&gt;compliance-specific policies&lt;/a&gt; for regulatory requirements and implement &lt;a href="https://www.pulumi.com/docs/iac/crossguard/get-started/#enforcing-a-policy-pack"&gt;server-side enforcement&lt;/a&gt; to ensure policies can&amp;rsquo;t be bypassed. Create formal processes for policy exemptions and exceptions, and begin measuring policy effectiveness through metrics like violation rates and remediation times.&lt;/p&gt;
&lt;p&gt;Remember that policy implementation is never &amp;ldquo;done.&amp;rdquo; Continuously monitor violation patterns to identify areas where policies might be too strict or too lenient. Refine policies based on developer feedback and incident data, add &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/core-concepts#remediation-policies"&gt;automated remediation&lt;/a&gt; for common violations to reduce manual fixes, and gradually expand coverage to new services and teams using lessons learned from early adopters.&lt;/p&gt;
&lt;h2 id="measuring-policy-success"&gt;Measuring Policy Success&lt;/h2&gt;
&lt;p&gt;You can&amp;rsquo;t improve what you don&amp;rsquo;t measure, and policy effectiveness is no exception. Successful teams track metrics across three critical dimensions to validate their policy strategy.&lt;/p&gt;
&lt;p&gt;From a security perspective, start by monitoring your policy violation rate: the percentage of deployments that trigger policy warnings or blocks. This tells you whether your policies are catching real issues or creating unnecessary friction. Track time to remediation to understand how quickly teams fix violations when they occur. Most importantly, measure the reduction in security incidents caused by misconfigurations. If your policies aren&amp;rsquo;t reducing incidents, they&amp;rsquo;re not addressing the right risks.&lt;/p&gt;
&lt;p&gt;Security is only half the equation, though. The developer experience dimension is equally important. Monitor deployment velocity to ensure policies aren&amp;rsquo;t slowing teams down. Regular developer satisfaction surveys reveal whether teams see policies as helpful guardrails or annoying obstacles. Track support ticket volume; successful policy implementation should reduce infrastructure-related requests as teams become more self-sufficient.&lt;/p&gt;
&lt;p&gt;Finally, don&amp;rsquo;t forget to measure the operational health of your policy system itself. Policy coverage shows what percentage of your resources are protected by policies, while the exemption rate reveals whether policies are practical or if teams constantly need exceptions. Track remediation automation to see how many violations are fixed automatically versus requiring manual intervention. Together, these metrics paint a complete picture of your policy program&amp;rsquo;s health and help you continuously improve your approach.&lt;/p&gt;
&lt;h2 id="common-pitfalls-and-how-to-avoid-them"&gt;Common Pitfalls and How to Avoid Them&lt;/h2&gt;
&lt;p&gt;Even with the best intentions, policy implementations can go wrong. Through years of helping organizations implement policy as code, we&amp;rsquo;ve identified four critical pitfalls that can derail your efforts.&lt;/p&gt;
&lt;p&gt;The first and most common trap is over-engineering policies. It&amp;rsquo;s tempting to create sophisticated policies that handle every edge case, but overly complex policies are hard to understand and maintain. Teams won&amp;rsquo;t trust what they don&amp;rsquo;t understand. Instead, start with simple, clear policies that address specific risks. Use descriptive naming and provide examples of both compliant and non-compliant configurations. Remember, a simple policy that everyone follows is better than a perfect policy that everyone circumvents.&lt;/p&gt;
&lt;p&gt;Equally dangerous is falling into &amp;ldquo;policy theater&amp;rdquo;: implementing policies because you think you should, not because they address real risks. This creates friction without improving security. Every policy should trace back to an actual incident, security requirement, or compliance need. If you can&amp;rsquo;t explain why a policy exists with a concrete example, it probably shouldn&amp;rsquo;t exist.&lt;/p&gt;
&lt;p&gt;Poor developer experience is another common failure point. Nothing kills policy adoption faster than cryptic error messages and unclear remediation steps. When a developer hits a policy violation at 5 PM on a Friday, they need clear guidance on how to fix it. Invest heavily in documentation, helpful error messages, and examples. Consider your policies&amp;rsquo; error messages as part of your product&amp;rsquo;s user experience.&lt;/p&gt;
&lt;p&gt;Finally, inadequate testing can erode trust quickly. Policies that break legitimate use cases will be worked around or disabled. Before enforcing any policy, test it thoroughly with real scenarios from your production workloads. Run policies in advisory mode first to catch false positives, and have teams attempt real deployments with policies enabled to ensure they don&amp;rsquo;t block valid configurations.&lt;/p&gt;
&lt;h2 id="the-future-of-policy-as-code"&gt;The Future of Policy as Code&lt;/h2&gt;
&lt;p&gt;As infrastructure becomes increasingly complex and distributed, policy as code is evolving beyond simple rule enforcement to become an intelligent layer that understands context and intent. Three major trends are shaping this evolution.&lt;/p&gt;
&lt;p&gt;First, we&amp;rsquo;re seeing the emergence of AI-enhanced policies with smart detection systems that use machine learning to identify anomalies that rule-based policies might miss. These systems learn from your infrastructure patterns and can provide contextual recommendations that adapt based on actual usage. Even more exciting is predictive enforcement: imagine policies that can identify risky patterns before they become violations, guiding developers away from problems they haven&amp;rsquo;t encountered yet.&lt;/p&gt;
&lt;p&gt;Second, the multi-cloud reality is driving the need for universal governance. Organizations need policies that work seamlessly across &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies-aws"&gt;AWS&lt;/a&gt;, &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies-azure"&gt;Azure&lt;/a&gt;, and &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies-gcp"&gt;GCP&lt;/a&gt;, with federated enforcement that maintains consistency across multiple cloud accounts and regions. Compliance automation is also maturing, with systems that automatically collect evidence for audits and generate compliance reports without manual intervention.&lt;/p&gt;
&lt;p&gt;Finally, policy enforcement is moving closer to where developers actually work. IDE integration will soon provide real-time policy feedback as you write infrastructure code, catching issues before you even attempt to deploy. Self-service exemption workflows will let developers request and receive policy exceptions through automated approval processes. Perhaps most intriguingly, we&amp;rsquo;re seeing the development of learning policies: systems that improve and adapt based on developer feedback and usage patterns, becoming more helpful over time rather than more restrictive.&lt;/p&gt;
&lt;h2 id="conclusion-enabling-safe-self-service-at-scale"&gt;Conclusion: Enabling Safe Self-Service at Scale&lt;/h2&gt;
&lt;p&gt;We started this post with a fundamental tension in platform engineering: the need for both speed and safety. Through the lens of Statsig&amp;rsquo;s transformation and the technical deep-dive into Pulumi CrossGuard, we&amp;rsquo;ve seen that this isn&amp;rsquo;t actually a tension that needs resolving. It&amp;rsquo;s a false dichotomy that policy as code eliminates entirely.&lt;/p&gt;
&lt;p&gt;The key insight from successful platform teams like Statsig is that guardrails don&amp;rsquo;t restrict freedom; they enable it. When developers know that automated policies will catch dangerous configurations, they gain the confidence to move fast and experiment. When platform teams know that policies automatically enforce security and compliance standards, they can focus on building better platforms instead of reviewing every change. This is the magic of policy as code: it transforms infrastructure governance from a bottleneck into an accelerator.&lt;/p&gt;
&lt;p&gt;But perhaps the most important lesson is that policy as code isn&amp;rsquo;t about saying &amp;ldquo;no&amp;rdquo; to developers. It&amp;rsquo;s about intelligent automation that makes the secure path the path of least resistance. It&amp;rsquo;s about catching mistakes before they become incidents. It&amp;rsquo;s about encoding your organization&amp;rsquo;s hard-won knowledge into systems that help every developer benefit from that experience.&lt;/p&gt;
&lt;p&gt;As you embark on your own journey to implement deployment guardrails, remember that perfection isn&amp;rsquo;t the goal; progress is. Start small, iterate based on feedback, and gradually expand your coverage. Your developers will thank you for the clarity and confidence that comes with well-designed guardrails, and your security team will sleep better knowing that policies are enforced automatically and consistently.&lt;/p&gt;
&lt;p&gt;The path from manual reviews to automated guardrails is well-traveled and well-documented. Our &lt;a href="https://github.com/pulumi/workshops/tree/main/idp-component-policies/demo-policies"&gt;complete policy examples&lt;/a&gt; provide real-world implementations you can adapt to your needs, while the &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard"&gt;CrossGuard documentation&lt;/a&gt; offers deep technical details for advanced use cases. If you&amp;rsquo;re on AWS, &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/awsguard"&gt;AWSGuard&amp;rsquo;s pre-built policies&lt;/a&gt; offer immediate value, and our &lt;a href="https://www.pulumi.com/docs/iac/packages-and-automation/crossguard/compliance-ready-policies"&gt;compliance-ready policy catalog&lt;/a&gt; addresses specific regulatory requirements.&lt;/p&gt;
&lt;p&gt;The future of infrastructure management isn&amp;rsquo;t about choosing between developer autonomy and operational control. It&amp;rsquo;s about using policy as code to achieve both, creating platforms that are simultaneously powerful and safe, flexible and compliant, fast and secure.&lt;/p&gt;
&lt;p&gt;In our next post, we&amp;rsquo;ll explore Day 2 Platform Operations, diving into how to maintain infrastructure compliance after deployment and automatically remediate configuration drift. Because getting to production is just the beginning; keeping your infrastructure secure and compliant over time is where the real challenge lies.&lt;/p&gt;
&lt;section class="my-16"&gt;
&lt;div class="container mx-auto max-w-5xl md:flex my-8 align-top justify-center text-center"&gt;
&lt;div class="md:w3-/12 mr-4"&gt;
&lt;h2 class="no-anchor"&gt;Get Started with Pulumi&lt;/h2&gt;
&lt;p class="text-gray-700 dark:text-gray-300 text-sm"&gt;Use Pulumi's open-source SDK to create, deploy, and manage infrastructure on any cloud.&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="mx-auto max-w-4xl"&gt;
&lt;div class="tiles flex-wrap mt-4"&gt;
&lt;div class="pb-4 md:pr-4 md:w-1/2"&gt;
&lt;a class="tile p-8" href="https://www.pulumi.com/docs/iac/get-started/aws/"&gt;
&lt;img class="h-10 mx-auto" src="https://www.pulumi.com/logos/tech/aws.svg" alt="AWS" /&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="pb-4 md:w-1/2"&gt;
&lt;a class="tile p-8" href="https://www.pulumi.com/docs/iac/get-started/azure/"&gt;
&lt;img class="h-10 mx-auto" src="https://www.pulumi.com/logos/tech/azure.svg" alt="Azure" /&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="pb-4 md:pr-4 md:w-1/2"&gt;
&lt;a class="tile p-8" href="https://www.pulumi.com/docs/iac/get-started/gcp/"&gt;
&lt;img class="h-10 mx-auto" src="https://www.pulumi.com/logos/tech/gcp.svg" alt="Google Cloud" /&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;div class="pb-4 md:w-1/2"&gt;
&lt;a class="tile p-8" href="https://www.pulumi.com/docs/iac/get-started/kubernetes/"&gt;
&lt;img class="h-10 mx-auto" src="https://www.pulumi.com/logos/tech/k8s.svg" alt="Kubernetes" /&gt;
&lt;/a&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/section&gt;</description><author>Adam Gordon Bell</author><category>internal-developer-platform</category><category>platform-engineering</category><category>policy-as-code</category><category>crossguard</category><category>compliance</category><category>security</category><category>self-service</category><category>guardrails</category></item></channel></rss>