compliance.tf

What is a promotion gate?

A promotion gate is a check that an infrastructure or configuration change must pass before it advances between environments, for example staging to production; it normally calls for approval and assesses policy or coverage conditions.

Why it matters

NIST SP 800-128 and similar change management guidance call for review and approval before a change takes effect. Many audits also look for approval by someone other than the author. When configured to do so, a promotion gate checks this where the change becomes live, and it records the result.

How compliance.tf applies it

Within compliance.tf, each environment is tied to a config snapshot. Promotion means attaching a new snapshot to that environment. Protected environments, with production protected by default, execute the gate before anything changes:

CheckSeverityRaised when
null_candidate_snapshotblockNo candidate snapshot was provided
snapshot_not_approvedblockThe candidate snapshot lacks approval
sod_self_approvalblockSegregation of duties is enabled and the promoter is also the snapshot publisher
coverage_uncoveredblock or warn, controlled by the organization's coverage settingAn enabled framework contains clauses that the candidate leaves uncovered

The promotion continues only when no check reports block severity.

  • Preview: executes the identical gate without changing state. Because a warn outcome appears only in the preview response, save that response if the warning must remain on file.
  • Audit record: the promotion and its audit record commit as one atomic operation; a simultaneous change fails with HTTP 409.
  • Waivers (accepted exceptions stored alongside a promotion): fixed when promotion occurs. Later processing does not check their expiry again.
  • Rollback: restores the prior snapshot and retains the waivers.

By default, segregation of duties is disabled.

Sources

On this page

Ask AI about this

Help improve this page