Percorrer por data de Publicação, começado por "2026-07-28"
A mostrar 1 - 1 de 1
Resultados por página
Opções de ordenação
- Policy-as-code enforcement in DevSecOps pipelinesPublication . RESENDE, ALICE MIRANDA; Nogueira, Luís Miguel PinhoThe increasing adoption of DevOps and Continuous Integration and Continuous Delivery (CI/CD) pipelines has significantly accelerated software development and deployment processes. However, this acceleration has also intensified challenges related to security governance and regulatory compliance, particularly in cloud-native and infrastructure-as-code environments. DevSecOps has emerged as a response to these challenges by promoting the integration of security throughout the software delivery lifecycle, yet many security and compliance controls remain manually enforced, inconsistently applied, or introduced too late in the pipeline. Policy-as-Code (PaC) has gained attention as a promising approach for formalising security and compliance requirements as executable, machine-readable policies that can be automatically enforced. Despite growing industrial adoption, the scientific literature reveals a lack of systematic, lifecycle-oriented frameworks for integrating PaC into DevSecOps pipelines in a consistent, auditable, and scalable manner. This dissertation investigates how Policy-as-Code can be effectively integrated into DevSec- Ops environments, with a particular focus on early enforcement within CI/CD pipelines. The work analyses the current state of the art, identifies methodological and architectural gaps, and proposes a structured approach for defining, managing, and enforcing policies across different stages of the pipeline. The proposed approach is evaluated through a proof of concept implemented using controlled scenarios and synthetic Kubernetes workload manifests, considering detection effectiveness, integration feasibility, and performance overhead. The results aim to contribute to a clearer understanding of Policy-as-Code as a foundational governance mechanism for secure software delivery and to provide practical guidance for its adoption in modern DevSecOps workflows.
