Introducing Controls in Kosli
Defining a control in a policy document is easy. Proving that every build was evaluated against it - and that nothing non-compliant ever reached production - is the hard part.
Kosli's new Controls feature closes that gap. Every control is defined in Kosli, every build is evaluated against it, and deployments are gated automatically when the evidence isn't there.
That means:
Every control decision is recorded as evidence, build by build
Coverage shows exactly where a control is enforced across your environments
Non-compliant artifacts are stopped in the pipeline before they're ever deployed
In this video, Simon Castagna (Software Developer, Kosli) walks through the full lifecycle of a real binary provenance control: how it's defined, how trails are evaluated against a Rego policy, how the new decision attestation records the outcome, and how an SDLC control gate in the release pipeline enforces it.
👉 See how teams define and enforce SDLC controls by default: https://www.kosli.com/secure-sdlc-process-template/
⏱ Video Timeline
00:00 – What this video covers
00:16 – Defining a control: binary provenance
00:37 – Flows, trails, and attestations
01:16 – The new decision attestation
01:42 – The Decisions and Coverage tabs
02:32 – Evaluating a trail against a Rego policy
03:16 – Recording the decision in the build workflow
03:41 – Requiring the control in environment policies
04:07 – Gating deployments with an SDLC control gate
04:41 – Verifying what's running in the environment
🔗 Links
✅ Secure SDLC process template: https://www.kosli.com/secure-sdlc-process-template/
✅ The Control Group - claim your seat: https://www.kosli.com/the-control-group/
✅ Visit Kosli: https://www.kosli.com/
#Kosli #SDLC #DevOps