Platform & DevOps·Secrets, identity and the supply chain
the rule that every workload must set resource limits is a file with tests, and it fails the pipeline rather than a review.
Policy as code
Also calledpolicy-as-code, guardrails as code, OPA policy
Expressing organisational rules as executable, versioned, testable code evaluated automatically. It converts standards from documents people are supposed to have read into checks that run, and it makes exceptions explicit and reviewable rather than tacit. Rolling it out in report-only mode first is essential, because a policy applied to an existing estate always turns out to have more violations than anyone predicted.