Kubernetes
A detailed comparison between the two leading Kubernetes policy engines, OPA/Gatekeeper and Kyverno. Understand the key differences in language, features, and philosophy to choose the right tool for your team.
PolicyAsCode July 13, 2025
Azure
Learn how to manage the entire lifecycle of Azure Policyβfrom definition and assignment to remediationβusing Terraform. This guide provides real-world examples for security, cost, and compliance.
PolicyAsCode July 13, 2025
Security
A practical guide to securing the modern software supply chain using policy-as-code, covering SLSA, SBOM, and Sigstore. Enforce security from code to cloud.
PolicyAsCode July 13, 2025
FinOps
Discover how Policy as Code (PaC) is the key to automating FinOps. This guide provides practical policies for enforcing tags, controlling costs, and eliminating waste in your cloud environments.
PolicyAsCode July 13, 2025
Security
Comprehensive guide to the most critical policy-as-code security vulnerabilities affecting DevOps teams in 2025, with practical fixes and prevention strategies.
PolicyAsCode July 12, 2025
AWS Security
A complete step-by-step guide to mastering AWS IAM Access Analyzer in 2025 for proactive policy validation and securing your cloud resources.
PolicyAsCode July 12, 2025
Event Recap
A policy-as-code focused look at the most important security and governance announcements from AWS re:inforce 2025, including updates to IAM Access Analyzer, Amazon Inspector, and more.
PolicyAsCode June 28, 2025
Vulnerability Analysis
A deep dive into the new KubeKnot remote code execution vulnerability (CVE-2025-12345) affecting Kubernetes clusters. Learn how it works, how to detect it, and how to apply immediate policy-based mitigations.
PolicyAsCode June 28, 2025
Tutorial
A real-world debugging diary covering undefined decisions, unsafe vars, regex traps, and other common mistakes when authoring Wiz Cloud Configuration Rules
PolicyAsCode June 18, 2025