> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/harness-platform/use-harness-platform/governance/policy-as-code/policy-as-code-for-environments.md).

# Policy as Code for Environments

Learn how to create and enforce OPA policies on Harness environments.

Harness provides governance using Open Policy Agent (OPA), Policy Management, and Rego policies.

You can create a policy and apply it to all [environments](/continuous-delivery/use-continuous-delivery/cd-building-blocks/environments/create-environments.md) in your Account, Org, or Project. The policy is evaluated on environment-level events:

* **On Save** — evaluated when an environment is created or updated.

For more details, see the [Harness Governance Quickstart](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-quickstart.md).

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* [Harness Governance Overview](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-overview.md)
* [Harness Governance Quickstart](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-quickstart.md)
* Policies use the OPA authoring language Rego. For more information, see [OPA Policy Authoring](https://academy.styra.com/courses/opa-rego).

### Step 1: Add a policy <a href="#step-1-add-a-policy" id="step-1-add-a-policy"></a>

1. In Harness, go to **Account Settings** → **Policies** → **New Policy**.
2. Enter a **Name** for your policy and click **Apply**.
3. Add your Rego policy in the editor.

   You can write your own Rego policy or use a sample from the **Library** panel. Select the **Library** tab, choose **Entity: Environment** from the dropdown, and pick one of the built-in samples:

   ![Environment sample policies in the Library panel](https://173309742-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3F2TpHXhur2QtQnORSM9%2Fuploads%2Fgit-blob-1167ea206e3e271d5331d3861effafee02e40ee1%2Fenvironment-sample-policies.png?alt=media)

   Harness ships a sample policy for environments:

   * **Environment – Block prod environment type and empty variable description:** Prevents creating a production environment that has an empty variable description.

   Below is an example Rego policy you can use as a starting point.

**Block production environment type and empty variable descriptions**

```
package environment

deny[msg] {
  input.environmentEntity.type == "Production"
  msg := "Production type environment is not allowed"
}

deny[msg] {
  input.environmentEntity.variables[_].description == ""
  msg := "Variable description is required but not provided"
}
```

4. Click **Save**.

### Step 2: Add the policy to a policy set <a href="#step-2-add-the-policy-to-a-policy-set" id="step-2-add-the-policy-to-a-policy-set"></a>

After creating your policy, add it to a Policy Set before it can be enforced on environments.

1. Go to **Policies** → **Policy Sets** → **New Policy Set**.
2. Enter a **Name** and optional **Description** for the Policy Set.
3. In **Entity type**, select **Environment**.
4. In **On what event should the Policy Set be evaluated**, select **On Save**.
5. Click **Continue**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Existing environments are not automatically evaluated against new policies. Policies are applied only when an environment is saved (created or updated).</p></div>
6. In **Policy evaluation criteria**, click **Add Policy**.
7. In the **Select Policy** dialog, choose the scope (**Project**, **Org**, or **Account**) and select the policy you created.

   ![Select a policy for the policy set](https://173309742-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3F2TpHXhur2QtQnORSM9%2Fuploads%2Fgit-blob-d4e32baaeff2f627c6bc49fa5c53cce0f8da7c83%2Fselect-policy-for-policy-set.png?alt=media)
8. Select the severity and action for policy violations:
   * **Warn & continue** — a warning is displayed if the policy is not met, but the environment is saved and you can proceed.
   * **Error and exit** — an error is displayed and the environment is not saved if the policy is not met.
9. Click **Apply**, then click **Finish**.
10. The Policy Set is automatically set to **Enforced**. To disable enforcement, toggle off the **Enforced** button.

### Step 3: Apply the policy to an environment <a href="#step-3-apply-the-policy-to-an-environment" id="step-3-apply-the-policy-to-an-environment"></a>

After creating and enforcing your Policy Set, it is automatically evaluated whenever an environment is saved.

1. Go to **Deployments** → **Environments** → **New Environment** (or edit an existing environment).
2. Configure the environment and click **Save**.
3. Based on your selection in the Policy Evaluation criteria:
   * If the environment meets the policy, it is saved successfully.
   * If the environment violates the policy and the severity is **Warn & continue**, it is saved with a warning.
   * If the environment violates the policy and the severity is **Error and exit**, the save is blocked and an error is displayed.

### OnSave enforcement for Git-backed environments <a href="#onsave-enforcement-for-git-backed-environments" id="onsave-enforcement-for-git-backed-environments"></a>

When an environment is stored in Git, commits made directly to the Git repository bypass the Harness UI save flow. Harness now evaluates **onSave** policies when a Git-backed environment changes via a webhook, and surfaces the result on the environment detail page. An **Environment Validation Failed** badge appears in the environment header when the latest commit violates an **onSave** policy. If a pipeline execution references this environment, Harness fails the execution when the environment is resolved.

Go to [Enforce onSave policies on Git entities](/harness-platform/use-harness-platform/governance/policy-as-code/enforce-policies-on-git-backed-entities.md) to understand how this enforcement works across all Git-backed entity types.

### See also <a href="#see-also" id="see-also"></a>

* [Harness Governance Overview](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-overview.md)
* [Policy Samples](/harness-platform/use-harness-platform/governance/policy-as-code/sample-policy-use-case.md)

{% @harness-feedback/feedback module="harness-ai" pagePath="harness-ai/use-harness-platform/governance/policy-as-code/policy-as-code-for-environments" %}
