Skip to content
Open access

Reusing Policy-as-Code Across CI/CD and Kubernetes Admission Control: An Empirical Assessment of Governance Consistency

Jul 2026 · De Computis · Vol 15, pp. 453 · 0 citations · 17 references
Computer Science

TL;DR

Empirically evaluates a reusable multi-stage Policy-as-Code enforcement model based on a shared policy-definition layer implemented using the Open Policy Agent framework and its Rego policy language and demonstrates that a shared policy-definition layer can support consistent policy enforcement across complementary enforcement stages while enabling policy reuse without requiring duplicate policy implementations within the evaluated environment.

Abstract

Cloud-native software-delivery pipelines increasingly rely on Policy-as-Code (PaC) to automate security, compliance, and governance enforcement. Although Policy-as-Code is widely adopted within Continuous Integration (CI) pipelines and Kubernetes admission-control frameworks, governance requirements are often implemented independently, potentially increasing maintenance effort and creating opportunities for policy drift. Despite the growing adoption of Policy-as-Code, comparatively little empirical evidence exists regarding the reuse of a shared policy-definition layer across complementary enforcement stages within the software-delivery lifecycle. This paper presents and empirically evaluates a reusable multi-stage Policy-as-Code enforcement model based on a shared policy-definition layer implemented using the Open Policy Agent (OPA) framework and its Rego policy language. Rather than proposing a new Policy-as-Code technology, the study investigates whether a shared policy-definition layer can support consistent policy enforcement across Continuous Integration validation and Kubernetes admission control. The model was evaluated using Conftest and OPA Gatekeeper through a structured experimental study comprising 29 Kubernetes manifests, 37 experimental scenarios, eight Kubernetes resource types, and 261 policy assertions covering representative cloud-native workload-governance requirements. Within the evaluated dataset, all intentionally introduced insecure configurations were correctly identified without observed false positives or false negatives. The shared policy-definition layer was successfully reused across both validation stages, while Kubernetes admission control mitigated all evaluated CI bypass scenarios by providing an independent deployment-time enforcement boundary. The results demonstrate that a shared policy-definition layer can support consistent policy enforcement across complementary enforcement stages while enabling policy reuse without requiring duplicate policy implementations within the evaluated environment. More broadly, the study contributes empirical evidence supporting policy reuse as a governance strategy for cloud-native software delivery and provides a reproducible foundation for future investigations involving larger datasets, broader governance-policy portfolios, alternative Policy-as-Code ecosystems, and production-scale deployments.

Read PDF

Similar papers

Jul 2026

ReATest: enhancing policy-as-code workflows through automated test case generation from Rego policies

ReATest is introduced, an automated approach to enhancing PaC workflows through systematic test case generation from Rego specifications, which achieves an average 35.43% reduction in test suite size and retains 64.57% of the generated test cases.

Thanh-Binh Trinh, N. Le, H. Nguyen · 0 citations
Open access Aug 2026

OpenGRCRMF: A Vendor-Neutral Framework for Teaching and Modeling RMF Automation, Continuous Authorization, and Zero Trust Governance

Abstract—Federal and regulated organizations continue to rely on document-centric Authorization to Operate (ATO) processes even as the NIST Risk Management Framework (RMF), continuous monitoring guidance, Zero Trust Architecture (ZTA), and continuous authorization initiatives require more continuous, evidence-driven ri...

Anand Janjal · 0 citations
#software testing Review Open access Sep 2026

Infrastructure as Code Security: A Review of Automation, Compliance, and Risk Management

Infrastructure as Code (IaC) has become an important approach for automating the provisioning, configuration, validation, and management of cloud and software infrastructure. This review covers five aspects of IaC: DevOps integration, security, automation, compliance, validation, and risk management. By version control...

Swapnil Joshi · 0 citations
2026

DevSecOps policy-as-code: Detecting and remediating over-privileged access tokens in SDLC tools

The article represents a Proof of Concept (PoC) for policy-as-code methodology designed to detect “Privilege Sprawl” in GitLab CI/CD environments and showed how teams can reduce their organisational exposure by 73% and get back into compliance with Least Privilege.

V. Havryliak, S. Vasylyshyn · 0 citations
Conference Aug 2026

Federated Data Residency Enforcement in Hybrid OpenShift

The rapid expansion of global enterprise applications and multi-cloud infrastructures has significantly increased the need for strict data governance and regulatory compliance. With the rise of region-specific data protection laws, organizations are now required to ensure that sensitive data remains within defined geog...

Siva Kantha Rao Vanama, Rama Krishna Kumar Lingamgunta, Abhijit Ubale · 0 citations
Open access Jun 2025

ESG-as-Code: A Deterministic Rule-Based Framework for Automated ESG Compliance Validation

Environmental, Social, and Governance (ESG) compliance has shifted from voluntary best practice to enforceable legal obligation across major global jurisdictions. Frameworks such as the European Union's Corporate Sustainability Reporting Directive (CSRD), the Sustainable Finance Disclosure Regulation (SFDR), the United...

Isaiah Oluwsegun Owolabi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.