Make the insecure configuration impossible to deploy

applied · 80 min · Objective 3.1

Task

Write infrastructure as code that deploys something insecure, then add the automated policy check that refuses it — a guard rail. Moving from 'we detect it afterwards' to 'it cannot be created' is the single most valuable pattern in this objective.

Steps

  1. Write /tmp/infra/storage.yaml: a small declarative description of a storage bucket with public: true, encryption: none, logging: false and a literal admin_password: Winter2026 written straight into the file. This is the configuration you are going to make undeployable.
  2. Write a second file /tmp/infra/storage-good.yaml with the same resource configured correctly, and the password replaced by a reference to a secrets manager, such as admin_password_ref: vault:lab/storage-admin. Secrets are referenced, never embedded.
  3. Write /tmp/policy.py: it reads the YAML file named on its command line and fails, naming the file and the rule, if any resource is public, unencrypted, has logging disabled, or holds a literal value under a key containing password, secret or token (a key ending _ref is a reference and passes).
  4. Run it and confirm it rejects the first file and accepts the second. A policy that rejects both is not discriminating.
  5. Now wire it as a guard rail rather than a report: write /tmp/deploy.sh that runs the policy check FIRST and refuses to proceed to the deployment step on a non-zero exit. The deployment step prints deploying <file> -- the word the Verify looks for.
  6. Prove the guard rail holds: run deploy.sh against the bad file and confirm the deployment step never executes, then against the good one and confirm it does.

Verify

python3 /tmp/policy.py /tmp/infra/storage-good.yaml; echo "good exit: $?"
python3 /tmp/policy.py /tmp/infra/storage.yaml; echo "bad exit: $?"
python3 /tmp/policy.py /tmp/infra/storage.yaml 2>&1 | grep -ciE "password|secret"
bash /tmp/deploy.sh /tmp/infra/storage.yaml 2>&1 | grep -ci "deploying"
bash /tmp/deploy.sh /tmp/infra/storage-good.yaml 2>&1 | grep -ci "deploying"

The good file must exit 0 and the bad file non-zero, and the third line must be non-zero: the policy named the embedded password, so the secrets rule fired rather than the file failing on its other faults alone. The fourth must be 0 -- the word deploying never appears, because the guard rail stopped before that step. The fifth must be non-zero. A guard rail that logs a warning and proceeds is a report, and the distinction is the entire point of the lab.

Notes

Notice where the security review has moved: it is no longer a meeting, it is a check that runs on every change, and the misconfiguration is not detected and remediated — it never exists. That is what the lesson means by security moving left, and it is why IaC concentrates risk in the repository and the pipeline.

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.