Make the insecure configuration impossible to deploy
Task
Write infrastructure as code that deploys something insecure, then add the automated policy check that refuses it — a guard rail. Moving from 'we detect it afterwards' to 'it cannot be created' is the single most valuable pattern in this objective.
Steps
- Write
/tmp/infra/storage.yaml: a small declarative description of a storage bucket withpublic: true,encryption: none,logging: falseand a literaladmin_password: Winter2026written straight into the file. This is the configuration you are going to make undeployable. - Write a second file
/tmp/infra/storage-good.yamlwith the same resource configured correctly, and the password replaced by a reference to a secrets manager, such asadmin_password_ref: vault:lab/storage-admin. Secrets are referenced, never embedded. - Write
/tmp/policy.py: it reads the YAML file named on its command line and fails, naming the file and the rule, if any resource is public, unencrypted, has logging disabled, or holds a literal value under a key containingpassword,secretortoken(a key ending_refis a reference and passes). - Run it and confirm it rejects the first file and accepts the second. A policy that rejects both is not discriminating.
- Now wire it as a guard rail rather than a report: write
/tmp/deploy.shthat runs the policy check FIRST and refuses to proceed to the deployment step on a non-zero exit. The deployment step printsdeploying <file>-- the word the Verify looks for. - Prove the guard rail holds: run
deploy.shagainst the bad file and confirm the deployment step never executes, then against the good one and confirm it does.
Verify
python3 /tmp/policy.py /tmp/infra/storage-good.yaml; echo "good exit: $?"
python3 /tmp/policy.py /tmp/infra/storage.yaml; echo "bad exit: $?"
python3 /tmp/policy.py /tmp/infra/storage.yaml 2>&1 | grep -ciE "password|secret"
bash /tmp/deploy.sh /tmp/infra/storage.yaml 2>&1 | grep -ci "deploying"
bash /tmp/deploy.sh /tmp/infra/storage-good.yaml 2>&1 | grep -ci "deploying"
The good file must exit 0 and the bad file non-zero, and the third line must be non-zero: the policy named the embedded password, so the secrets rule fired rather than the file failing on its other faults alone. The fourth must be 0 -- the word deploying never appears, because the guard rail stopped before that step. The fifth must be non-zero. A guard rail that logs a warning and proceeds is a report, and the distinction is the entire point of the lab.
Notes
Notice where the security review has moved: it is no longer a meeting, it is a check that runs on every change, and the misconfiguration is not detected and remediated — it never exists. That is what the lesson means by security moving left, and it is why IaC concentrates risk in the repository and the pipeline.
This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.