NORMA eResearch @NCI Library

Healthcare-Grade Cross-Cloud Policy Delivery: Signed OPA Bundles as OCI Artifacts on AWS, Azure & GCP

Maddipoti, Lakshmi Prasanna (2025) Healthcare-Grade Cross-Cloud Policy Delivery: Signed OPA Bundles as OCI Artifacts on AWS, Azure & GCP. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (1MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (1MB) | Preview

Abstract

Healthcare organisations increasingly operate workloads across multiple public clouds to improve uptime, cost efficiency, and regional coverage. In such environments, access-control and compliance policies must remain consistent wherever protected health data is processed, while also being tamper evident and auditable to support regulatory expectations associated with HIPAA/HITECH and GDPR. In practice, however, policies are often distributed through manual file copying, informal syncing scripts, or mutable tags, which creates configuration mismatch over time and introduces time-of-check/time-of-use risk: the same reference can silently point to different policy content over time. This thesis examines whether treating policy-as-code as a primary supply-chain artifact can provide a provider-neutral foundation for healthcare-grade policy delivery across AWS, Azure, and GCP. It proposes and implements a reference workflow in which Open Policy Agent (OPA) policy bundles are packaged in a repeatable way, tied to immutable content digests, published through standard OCI-compatible registries, and protected by cryptographic signatures attached as associated artifacts. A CLI-first toolchain runs the pipeline end-to-end build, sign, publish/discover, verify, and execute while emitting machine-readable evidence suitable for audit import. A prototype implementation demonstrates verify-before-use enforcement gating (fail closed), structured evidence generation, and tamper detection via deliberate small change of the bundle payload and signature material. The results support the claim that digest-tied, signed policy artifacts can reduce mismatch over time, strengthen integrity guarantees, and improve audit readiness without cloud-specific policy distribution mechanisms. The thesis concludes with an extensible evaluation framework and practical guidance for expanding the approach into full cross-cloud registry deployments and operational oversight workflows.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Heeney, Sean
UNSPECIFIED
Uncontrolled Keywords: Policy-as-Code; Open Policy Agent (OPA); OCI artifacts; container registries; content digests; Sigstore/Cosign; supply chain security; tamper-evidence; origin record; auditability; multi-cloud compliance; healthcare security
Subjects: T Technology > T Technology (General) > Information Technology > Cloud computing
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
K Law > KDK Republic of Ireland > Data Protection
R Medicine > Healthcare Industry
Divisions: School of Computing > Master of Science in Cloud Computing
Depositing User: Ciara O'Brien
Date Deposited: 01 Sep 2026 09:02
Last Modified: 01 Sep 2026 09:02
URI: https://norma.ncirl.ie/id/eprint/9718

Actions (login required)

View Item View Item