# Terraform and OpenTofu policy governance | ZopNight

> Check every Terraform and OpenTofu plan against policies from 70 built-in rules or your own Rego, with the monthly cost in the PR. Never runs apply.

Source: https://zop.dev/zopnight/iac-governance

---

_Never runs apply_

## Policy on every Terraform plan.

ZopNight checks every Terraform and OpenTofu plan against your policies and reports on the pull request, with the monthly cost of the change beside it. Your own GitHub check decides whether it merges. ZopNight never runs apply.

- 70 — built-in rules to choose from
- Rego — for policies of your own
- $/mo — cost of each plan, in the PR
- Never — runs apply

Free to start. No card. The playground just needs your work email.

## It decides. You enforce.

A policy decision point, never an actor on your infrastructure.

- 01. Wire it in — ZopNight opens a pull request that adds a Terraform-aware GitHub Action to your repo, with its own scoped scan token.
- 02. Check the plan — Every plan runs against the policies you attach, chosen from 70 built-in rules across security, IAM, networking, cost, reliability, Kubernetes and more, or written in Rego.
- 03. Price the change — Cost guardrails put the monthly figure in the PR: a hard cap, a total budget, or a maximum increase. Engineers see the bill before they merge.
- 04. You enforce it — Every run comes back Passed, Advisory or Blocked. A block stops the merge once you make the check required in GitHub. Overrides are allowed, and every one is audited.

## Guardrails with a clear edge.

What it checks, and what it will never do.

- Scope: Your own Terraform and OpenTofu, read from plan output on each PR and from state for an inventory scan. Declared resources are matched to what is actually running.
- Frameworks: Rules map to CIS, PCI-DSS, SOC 2, HIPAA, NIST 800-53 and FinOps, wherever a mapping applies.
- Custom policy: Real OPA running sandboxed Rego, with no network and no clock. It only loads when a custom policy exists.
- Boundary: A decision point, never an actor. ZopNight does not run apply and never changes your infrastructure.

## Make the cost visible before the merge.

Connect a repo and the first plan is checked on its next pull request.

[object Object]
