> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/harness-platform/use-harness-platform/governance/policy-as-code/policy-as-code-for-infrastructure.md).

# Policy as Code for Infrastructure

Learn how to create and enforce OPA policies on Harness infrastructure definitions.

Harness provides governance using Open Policy Agent (OPA), Policy Management, and Rego policies.

You can create a policy and apply it to all [infrastructure definitions](/continuous-delivery/new-to-continuous-delivery/overview.md#infrastructure-definition) in your Account, Org, or Project. The policy is evaluated on infrastructure-level events:

* **On Save** — evaluated when an infrastructure definition is created or updated.
* **On Run** — evaluated when a pipeline that references the infrastructure definition is executed.

For more details, see the [Harness Governance Quickstart](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-quickstart.md).

### Prerequisites <a href="#prerequisites" id="prerequisites"></a>

* [Harness Governance Overview](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-overview.md)
* [Harness Governance Quickstart](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-quickstart.md)
* Policies use the OPA authoring language Rego. For more information, see [OPA Policy Authoring](https://academy.styra.com/courses/opa-rego).

### Step 1: Add a policy <a href="#step-1-add-a-policy" id="step-1-add-a-policy"></a>

1. In Harness, go to **Account Settings** → **Policies** → **New Policy**.
2. Enter a **Name** for your policy and click **Apply**.
3. Add your Rego policy in the editor.

   You can write your own Rego policy or use a sample from the **Library** panel. Select the **Library** tab, choose **Entity: Infrastructure** from the dropdown, and pick one of the built-in samples:

   ![Infrastructure sample policies in the Library panel](https://173309742-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3F2TpHXhur2QtQnORSM9%2Fuploads%2Fgit-blob-379c024a47221cda32c1bd1b4f633a339e2d8abb%2Finfrastructure-sample-policies.png?alt=media)

   Harness ships a sample policy for infrastructure definitions:

   * **Infrastructure – Block runtime input for connector and namespace:** Prevents infrastructure definitions from using runtime inputs (`<+input>`) for the connector or namespace fields.

   Below is the Rego policy for this sample.

**Block runtime inputs for connector and namespace**

This policy denies infrastructure definitions that use runtime inputs for the `connectorRef` or `namespace` fields. This ensures that teams explicitly set these values rather than deferring them to pipeline execution time.

```
package infra

deny[msg] {
  input.infrastructureEntity.spec.connectorRef == "<+input>"
  msg := "Runtime input is not allowed for connector"
}

deny[msg] {
  input.infrastructureEntity.spec.namespace == "<+input>"
  msg := "Runtime input is not allowed for namespace"
}
```

4. Click **Save**.

### Step 2: Add the policy to a policy set <a href="#step-2-add-the-policy-to-a-policy-set" id="step-2-add-the-policy-to-a-policy-set"></a>

After creating your policy, add it to a Policy Set before it can be enforced on infrastructure definitions.

1. Go to **Policies** → **Policy Sets** → **New Policy Set**.
2. Enter a **Name** and optional **Description** for the Policy Set.
3. In **Entity type**, select **Infrastructure**.
4. In **On what event should the Policy Set be evaluated**, select **On Save**, **On Run**, or both depending on when you want the policy enforced.
   * **On Save** — the policy is evaluated every time a user creates or updates the infrastructure definition.
   * **On Run** — the policy is evaluated when a pipeline that uses the infrastructure definition is executed.
5. Click **Continue**.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Existing infrastructure definitions are not automatically evaluated against new policies. Policies are applied only when an infrastructure definition is saved (created or updated) or when a pipeline referencing it is run.</p></div>
6. In **Policy evaluation criteria**, click **Add Policy**.
7. In the **Select Policy** dialog, choose the scope (**Project**, **Org**, or **Account**) and select the policy you created.

   ![Select a policy for the policy set](https://173309742-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3F2TpHXhur2QtQnORSM9%2Fuploads%2Fgit-blob-d4e32baaeff2f627c6bc49fa5c53cce0f8da7c83%2Fselect-policy-for-policy-set.png?alt=media)
8. Select the severity and action for policy violations:
   * **Warn & continue** — a warning is displayed if the policy is not met, but the infrastructure definition is saved and you can proceed.
   * **Error and exit** — an error is displayed and the infrastructure definition is not saved if the policy is not met.
9. Click **Apply**, then click **Finish**.
10. The Policy Set is automatically set to **Enforced**. To disable enforcement, toggle off the **Enforced** button.

### Step 3: Apply the policy to an infrastructure definition <a href="#step-3-apply-the-policy-to-an-infrastructure-definition" id="step-3-apply-the-policy-to-an-infrastructure-definition"></a>

After creating and enforcing your Policy Set, it is automatically evaluated whenever an infrastructure definition event matches the configured trigger.

1. Go to **Deployments** → **Environments** → select an environment → **Infrastructure Definitions**.
2. Create or edit an infrastructure definition and click **Save**.
3. Based on your selection in the Policy Evaluation criteria:
   * If the infrastructure definition meets the policy, it is saved successfully.
   * If the infrastructure definition violates the policy and the severity is **Warn & continue**, it is saved with a warning.
   * If the infrastructure definition violates the policy and the severity is **Error and exit**, the save is blocked and an error is displayed.

### OnSave enforcement for Git-backed infrastructure definitions <a href="#onsave-enforcement-for-git-backed-infrastructure-definitions" id="onsave-enforcement-for-git-backed-infrastructure-definitions"></a>

When an infrastructure definition is stored in Git, commits made directly to the Git repository bypass the Harness UI save flow. Harness now evaluates **onSave** policies when a Git-backed infrastructure definition changes via a webhook, and surfaces the result in the infrastructure details drawer. An **Infrastructure Validation Failed** badge appears when the latest commit violates an **onSave** policy. If a pipeline execution references this infrastructure definition, Harness fails the execution at the infrastructure resolution step.

Go to [Enforce onSave policies on Git entities](/harness-platform/use-harness-platform/governance/policy-as-code/enforce-policies-on-git-backed-entities.md) to understand how this enforcement works across all Git-backed entity types.

### See also <a href="#see-also" id="see-also"></a>

* [Harness Governance Overview](/harness-platform/use-harness-platform/governance/policy-as-code/harness-governance-overview.md)
* [Policy Samples](/harness-platform/use-harness-platform/governance/policy-as-code/sample-policy-use-case.md)

{% @harness-feedback/feedback module="harness-ai" pagePath="harness-ai/use-harness-platform/governance/policy-as-code/policy-as-code-for-infrastructure" %}
