Policy as Code: Automated Compliance Enforcement Using Open Policy Agent Across Multi-Tenant Kubernetes Clusters

research-article
Received: Jun 5, 2023
Published: Jul 20, 2023
Authors:

Abstract

Regulated industries operating Kubernetes at scale face continuous compliance challenges spanning CIS benchmarks, SOC 2, and PCI-DSS controls. This paper demonstrates a Policy as Code architecture using Open Policy Agent (OPA) and Gatekeeper to enforce 147 compliance controls across multi-tenant Kubernetes clusters in a financial services firm. The policy lifecycle�authoring, testing, staging, and enforcement�is fully integrated into the GitOps delivery pipeline. Automated compliance reporting reduced manual audit effort by 68% and eliminated configuration drift violations within two quarters of deployment. A library of reusable, community-contributed Rego policies and a policy testing harness are released as open-source artefacts.

⬇ Download

Cite this article

(2023). Policy as Code: Automated Compliance Enforcement Using Open Policy Agent Across Multi-Tenant Kubernetes Clusters. Research Explorations in Global Knowledge & Technology (REGKT), 3 (5). Retrieved from https://regkt.com/article.php?id=862&slug=policy-as-code-automated-compliance-open-policy-agent-multi-tenant-kubernetes

Premium Membership Required

You need a premium account to view or download this article.

Become Premium