Safe Terraform auto-apply with conftest
Summary
The article argues for policy-as-code to safely auto-apply Terraform plans. It shows using conftest (OPA) to evaluate the Terraform JSON plan against Rego rules, enabling auditable, deterministic gate in CI/CD. Includes example policies and pipeline wiring.