Skip to content

Lesson 2: Policy-as-Code (Checkov & OPA)

🧠 The Concept (Explain Like I'm 5)

Imagine spelling and grammar check in Microsoft Word. If you misspell a word, it underlines it in red before you print the document. Checkov and OPA (Open Policy Agent) do this for Cloud Infrastructure. If a developer writes Terraform that opens port 22 (SSH) to the entire internet (0.0.0.0/0), the tool catches it and fails the build before it gets deployed to AWS.


🏢 The Enterprise Context

  • Shift-Left Security: Catching a misconfiguration in CI/CD costs $10. Catching it in Production during a security breach costs $10,000,000.
  • Compliance: Rego (OPA's language) allows security teams to write rules like "S3 Buckets must have encryption enabled."

🗺️ Visual Architecture: Shift-Left CI/CD

flowchart LR
    Dev["Developer<br/>(git push)"] --> CI["GitHub Actions / CI"]

    subgraph Pipeline ["CI Pipeline"]
        Fmt["terraform fmt"] --> Validate["terraform validate"]
        Validate --> Checkov{"Checkov Scan"}
    end

    CI --> Pipeline
    Checkov -->|Vulnerability Found| Block["❌ Fail Build"]
    Checkov -->|Passes| Plan["terraform plan"]
    Plan --> Deploy["Deploy to AWS"]