NORMA eResearch @NCI Library

Automated, Multi-Environment, scalable CI-CD pipeline orchestration with Open Policy Agent and Terraform for AWS Cloud policy-as-code enforcement

Vanjarapu, Avinash (2025) Automated, Multi-Environment, scalable CI-CD pipeline orchestration with Open Policy Agent and Terraform for AWS Cloud policy-as-code enforcement. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (1MB) | Preview

Abstract

The growth of cloud infrastructure and Infrastructure as Code (IaC) practices has made it necessary to have automated mechanisms for governance to make sure compliance and security at scale. Traditional manual processes of policy validation and deployment cause latency, inconsistency, and operational risk and hinder an organization’s ability to be agile in fast-moving cloud environments. This research outlines an automated multi-environment CI/CD pipeline design and implementation and evaluation of an automated multi-environment CI/CD pipeline to manage Open Policy Agent (OPA) policy lifecycle based on the principles of DevSecOps applied to policy-as-code workflow. The pipeline design makes use of AWS Code-Pipeline and codebuild to organize it, Terraform to deploy the infrastructure and nine levels of verification including secret supports, syntax validation, unit testing, integration testing, cryptographic signing and progressive deployment on the development, UAT and production environments. Experimental evaluation in 147 executions of a pipeline demonstrates 83.6% reduction in deployment time than manual processes (4.2 minutes v.s. 25.6 minutes), 97.1% of cost reduction per deployment and 52x improvement in deployment frequency capability. Security controls consisting of bundle cryptographic signing and automated scanning of secrets attained 100% signature verification success and zero false negative detection with no performance impact. The performance characteristics are in linear form, as demonstrated by the scalability analysis, indicating the ability of the developed repositories to handle 200 and more policies within 15 minutes. The implementation validates how automated policy as code implementation provides transformative improvements in speed, consistency, security and cost effectiveness for continuous compliance and automation of governance in cloud native environments.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Emani, Sai
UNSPECIFIED
Uncontrolled Keywords: Policy-as-Code; DevSecOps; CI/CD Automation; Open Policy Agent; Cloud Compliance; Infrastructure as Code; Continuous Integration; AWS CodePipeline; Automated Governance; Security Automation
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Cloud computing
Divisions: School of Computing > Master of Science in Cloud Computing
Depositing User: Ciara O'Brien
Date Deposited: 01 Sep 2026 12:05
Last Modified: 01 Sep 2026 12:05
URI: https://norma.ncirl.ie/id/eprint/9748

Actions (login required)

View Item View Item