Compliance Management of IaC-Based Cloud Deployments During Runtime

Compliance Management of IaC-Based Cloud Deployments During Runtime

Abstract

Modern cloud applications increasingly depend on Infrastructure-as-Code (IaC) practices for infrastructure automation to help manage the complexity of deploying large-scale architectures. Additionally, the deployment of cloud applications is commonly subject to compliance rules. Moreover, designing compliant IaC-based cloud deployments is not enough since runtime changes to the infrastructure or the configuration of individual components may introduce compliance violations. Often, the process of checking and fixing such violations is done manually, which is time-consuming and error-prone. Therefore, this work aims to define and implement a method for runtime IaC compliance management that reduces the complexity, effort, and uncertainty of checking and enforcing compliance rules against IaC-based cloud deployments at runtime. To this end, we follow the design-science research methodology to design and implement (i)~the Runtime IaC Compliance Management~(RICMa) method and (ii)~the IaC Compliance Management Framework~(IaCMF) that supports the execution of the RICMa method. We prototypically implement IaCMF and evaluate it using a qualitative interview study with industry experts.

Grafik Top
Authors
  • Falazi, Ghareeb
  • Harzenetter, Lukas
  • Képes, Kálmán
  • Leymann, Frank
  • Ntentos, Evangelos
  • Zdun, Uwe
  • Breitenbücher, Uwe
  • Becker, Martin
  • Heldwein, Elena
Grafik Top
Projects
Grafik Top
Shortfacts
Category
Paper in Conference Proceedings or in Workshop Proceedings (Paper)
Event Title
The 16th IEEE/ACM International Conference on Utility and Cloud Computing (UCC 2023)
Divisions
Software Architecture
Event Location
Taormina (Messina), Italy
Event Type
Conference
Event Dates
4 - 7 December 2023
Date
4 December 2023
Export
Grafik Top