• Jul 2026

    Executable NIST 800-53 Controls

    Three NIST 800-53 controls rewritten as Open Policy Agent rules with a full unit-test suite, so a non-compliant Terraform plan is rejected automatically instead of being caught in next quarter's sample.

    • SC-28
    • AC-3
    • CM-6
    • Open Policy Agent
    • Rego
    • Conftest
    • Terraform
    • Policy as Code
  • Jun 2026

    Compliant-by-Default AWS Storage

    Terraform that provisions S3 storage with encryption, versioning, access blocking, and audit logging enforced at creation time - so the control is satisfied before an auditor ever asks.

    • SC-28
    • CM-6
    • AC-3
    • AU-3
    • Terraform
    • AWS
    • S3
    • Infrastructure as Code

Labs

Smaller experiments - a single policy, a script, a proof of concept. Each links straight to its repo.

No labs posted yet.