Maddipoti, Lakshmi Prasanna (2025) Healthcare-Grade Cross-Cloud Policy Delivery: Signed OPA Bundles as OCI Artifacts on AWS, Azure & GCP. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (1MB) | Preview |
Preview |
PDF (Configuration Manual)
Download (1MB) | Preview |
Abstract
Healthcare organisations increasingly operate workloads across multiple public clouds to improve uptime, cost efficiency, and regional coverage. In such environments, access-control and compliance policies must remain consistent wherever protected health data is processed, while also being tamper evident and auditable to support regulatory expectations associated with HIPAA/HITECH and GDPR. In practice, however, policies are often distributed through manual file copying, informal syncing scripts, or mutable tags, which creates configuration mismatch over time and introduces time-of-check/time-of-use risk: the same reference can silently point to different policy content over time. This thesis examines whether treating policy-as-code as a primary supply-chain artifact can provide a provider-neutral foundation for healthcare-grade policy delivery across AWS, Azure, and GCP. It proposes and implements a reference workflow in which Open Policy Agent (OPA) policy bundles are packaged in a repeatable way, tied to immutable content digests, published through standard OCI-compatible registries, and protected by cryptographic signatures attached as associated artifacts. A CLI-first toolchain runs the pipeline end-to-end build, sign, publish/discover, verify, and execute while emitting machine-readable evidence suitable for audit import. A prototype implementation demonstrates verify-before-use enforcement gating (fail closed), structured evidence generation, and tamper detection via deliberate small change of the bundle payload and signature material. The results support the claim that digest-tied, signed policy artifacts can reduce mismatch over time, strengthen integrity guarantees, and improve audit readiness without cloud-specific policy distribution mechanisms. The thesis concludes with an extensible evaluation framework and practical guidance for expanding the approach into full cross-cloud registry deployments and operational oversight workflows.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Heeney, Sean UNSPECIFIED |
| Uncontrolled Keywords: | Policy-as-Code; Open Policy Agent (OPA); OCI artifacts; container registries; content digests; Sigstore/Cosign; supply chain security; tamper-evidence; origin record; auditability; multi-cloud compliance; healthcare security |
| Subjects: | T Technology > T Technology (General) > Information Technology > Cloud computing Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security K Law > KDK Republic of Ireland > Data Protection R Medicine > Healthcare Industry |
| Divisions: | School of Computing > Master of Science in Cloud Computing |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 01 Sep 2026 09:02 |
| Last Modified: | 01 Sep 2026 09:02 |
| URI: | https://norma.ncirl.ie/id/eprint/9718 |
Actions (login required)
![]() |
View Item |
Tools
Tools