What is policy-as-code?
Policy-as-code means expressing organizational and security rules in a machine-readable language, such as Rego or Sentinel, so a policy engine can evaluate configuration or a Terraform plan and allow or deny the change.
How it works
The engine takes structured data, most often the output of terraform show -json, and answers with pass, warn or deny. For Terraform, the usual engines are Open Policy Agent, which runs Rego policies, and HashiCorp Sentinel. HCP Terraform and Spacelift are examples of platforms that check policies after planning and before applying; a mandatory or blocking policy halts the run, whereas an advisory policy only records a finding.
A rule may read any resource and any attribute present in the plan, and it may branch on conditions like "only in production" or "only for this team". That scope suits naming, tagging, region and cost requirements.
Evaluation is separate from generation: the engine judges the plan and never alters Terraform's output. When a bucket has no encryption, the policy turns down the plan, so an engineer edits the code and plans again.
Policy-as-code compared with controls in the module
| Policy-as-code (OPA, Sentinel) | compliance.tf modules | |
|---|---|---|
| Rule location | A dedicated policy repository | Within the Terraform module |
| Absent secure setting | Turns the plan down | Provides that setting as a module default |
| Reach | Any resource present in the plan | Resources created through compliance.tf modules |
| Custom and conditional rules | Yes | No, controls are fixed per framework |
| Policy authoring effort | Write and test Rego or Sentinel | No policy code to write for covered controls |
How compliance.tf fits
compliance.tf is one kind of compliance-as-code: for the controls it covers, no policy engine is required. It is not a stand-in for one. Rules set by your organization, plus anything beyond the module catalog, remain work for your current OPA, Sentinel or Checkov policies.
ctfkit, the CI checker for compliance.tf, emits findings in formats a policy can consume; blocking is not its call. That decision belongs to an OPA, Sentinel or Spacelift policy.