September 2026 Summaries
2 posts from Spacelift
Filter
Month:
Year:
Post Summaries
Back to Blog
Infrastructure-as-code governance is presented as a security responsibility because consequential cloud configuration choices, such as access permissions, encryption, network exposure, and logging, are made in Terraform, OpenTofu, CloudFormation, Kubernetes manifests, and related code before deployment. The playbook recommends four continuous pillars: inventorying coded and unmanaged infrastructure while measuring drift and policy coverage; linking Git history, CI/CD records, and cloud logs into a reliable audit trail; introducing targeted policy-as-code checks gradually from warning to enforcement; and conducting recurring reviews of human and machine access, especially privileged CI roles and state-backend credentials. It advises prioritizing issues by potential impact and exploitability, with reusable insecure modules receiving particular urgency, and measuring progress through enforced-policy coverage, drift levels and duration, IaC adoption for changes, pipeline pass rates, and exceptions rather than raw finding totals. Common risks include treating governance as a finite project, deploying broad scanner rule sets or blocking controls too quickly, inadequately protecting Terraform state, lacking an accountable exception process, and failing to collaborate with platform and development teams. The text also describes Spacelift as an orchestration platform offering policy enforcement, drift detection, multi-IaC workflows, access features, and automated infrastructure management.
Sep 10, 2026
4,140 words in the original blog post.
Spacelift Flows, launched on September 8, 2026, is a visual workflow automation capability designed to bring governed, auditable infrastructure-as-code practices to Day 2 operations such as incident response, provisioning, drift handling, and cleanup. Users can build workflows from connected blocks for HTTP calls, transformations, conditions, and schedules, while receiving execution logs and step-level audit trails for troubleshooting and oversight. The product supports AI-assisted workflow creation and more than 40 templates for common use cases, including incident enrichment, certificate monitoring, environment provisioning, and Jira or ServiceNow self-service requests. Flows also provides a governed way for AI agents to interact with infrastructure through MCP servers, approval gates, distinct access paths, and traceable activity. Integrated natively with Spacelift Deploy, it can respond to infrastructure events such as stack changes, runs, and drift, allowing deployment and operational automation to operate under a shared control plane, governance model, and audit trail.
Sep 08, 2026
570 words in the original blog post.