Lesson 2: Policy-as-Code (Checkov & OPA)
🧠 The Concept (Explain Like I'm 5)
Imagine spelling and grammar check in Microsoft Word. If you misspell a word, it underlines it in red before you print the document.
Checkov and OPA (Open Policy Agent) do this for Cloud Infrastructure. If a developer writes Terraform that opens port 22 (SSH) to the entire internet (0.0.0.0/0), the tool catches it and fails the build before it gets deployed to AWS.
🏢 The Enterprise Context
- Shift-Left Security: Catching a misconfiguration in CI/CD costs $10. Catching it in Production during a security breach costs $10,000,000.
- Compliance: Rego (OPA's language) allows security teams to write rules like "S3 Buckets must have encryption enabled."
🗺️ Visual Architecture: Shift-Left CI/CD
flowchart LR
Dev["Developer<br/>(git push)"] --> CI["GitHub Actions / CI"]
subgraph Pipeline ["CI Pipeline"]
Fmt["terraform fmt"] --> Validate["terraform validate"]
Validate --> Checkov{"Checkov Scan"}
end
CI --> Pipeline
Checkov -->|Vulnerability Found| Block["❌ Fail Build"]
Checkov -->|Passes| Plan["terraform plan"]
Plan --> Deploy["Deploy to AWS"]