BlogsConfluentPolicy-as-Code for Terraform

Policy-as-Code for Terraform

Policy-as-Code for Terraform

3
posts
2022–2023

This post introduces the integration of policy-as-code with Confluent's Terraform provider, enabling self-service management of Confluent resources with automated enforcement of security, compliance, and auditing requirements. It details how policy-as-code is applied during the Terraform plan phase using HashiCorp Sentinel, with examples of policies for cloud provider and region restrictions, naming conventions, and RBAC role assignments. A Confluent Policy Library is provided to help users adopt.

2023

Self-Service GitOps for Policy-as-Code Systems in Confluent Cloud

6/1/2023

Introduces policy-as-code integration with Confluent's Terraform provider. Details the application of policies during the Terraform plan phase using HashiCorp Sentinel, including examples of policies for cloud provider restrictions, naming standards, and RBAC. Provides a Confluent Policy Library and discusses future plans for Open Policy Agent support.

2022

Confluent Terraform Provider (Now Generally Available)

9/27/2022

This post announces the general availability of the Confluent Terraform Provider, detailing its capabilities for managing Confluent Cloud resources (API keys, clusters, connectors, etc.) as code. It outlines prerequisites, provides a step-by-step guide for setting up Terraform configurations, creating cloud infrastructure, and testing deployments, including the use of environment variables for API keys and secrets. It also mentions the availability of resources and data sources within the provider and encourages users to refer to the changelog for future updates.

Terraform Provider & Network Management | Confluent's Q3 '22 Launch

7/19/2022

This post introduces the Confluent Terraform provider, enabling infrastructure as code for Confluent Cloud resources. It details how to manage Kafka clusters, private networks, connectors, and RBAC using Terraform, integrating with GitOps workflows. It also introduces independent network lifecycle management via REST APIs and Terraform, and a new NetworkAdmin role for granular access control. Additionally, it highlights the expansion of fully managed connectors to 70, including new source connectors for GCS, S3, and Azure Cosmos DB, and introduces flexible topic naming and a GUI for Cluster Linking, along with custom zone selection for networks on AWS and Google Cloud.