Practitioner notes on CI/CD security — what broke, what we built, and what it took to get teams to actually use it.
How we used OPA and Kyverno to turn security policy from a document nobody read into an automatic gate — privileged containers, unsigned images, and root access blocked before they ever reach production.
How we replaced inconsistent, team-by-team CI/CD security with a single set of versioned, account-level templates — and what changed once every pipeline inherited fixes automatically.