ProdgatorDocs
Compliance

Compliance, release and pull request policies

The three kinds of policy in Prodgator, what each one gates, and how they work together on the same deployment or pull request.

Prodgator has three kinds of policy. They are set up in different places and gate different things, but they can apply to the same deployment or repository.

Compliance policiesRelease policiesPull request policies
WhereCompliance pageGates > PoliciesGates > Policies, Used for Pull requests
GatesDeployments (Block mode, Enterprise)DeploymentsPull requests
Reports on GitHub asProdgator's protection rule; the status on pull requestsProdgator's protection ruleThe Prodgator Policies check run
Written asBuilt-in checks, each policy on or offForm rules or RegoForm rules or Rego
PlanBusiness; Enterprise to blockBusinessTeam (some rules need Business)
DocsCompliance policiesRelease policiesPull request gates

Release policies and compliance policies

Compliance policies and release policies both gate deployments through Prodgator's protection rule. When an enforce release policy is bound to a deployment, Prodgator answers the rule once, taking both into account:

  • If a block-mode compliance policy fails, the deployment is rejected, even if every release policy passes or is still waiting.
  • If a block-mode compliance policy is still waiting for CI, an approval from the release policies waits too.
  • The deployment is approved only when the release policies approve and compliance allows it.
  • An active break-glass override lets a deployment through a failing compliance policy, as it does without release policies. It does not override a release policy.

Blocking on compliance policies needs the Enterprise plan. On other plans compliance does not affect the answer.

Without an enforce release policy or a Block compliance policy on the environment, Prodgator does not answer the rule at all: the deployment waits for someone to approve it in Prodgator.

Compliance policies still apply

A release policy cannot approve past a failing compliance policy. A break-glass override is the one way through. Only an admin can create one, it covers one repository and environment for at most 24 hours, it needs a written reason, and every use is written to the audit log and to the comment on GitHub. It does not override a release policy.

While an enforce policy governs a deployment, approving it by hand in Prodgator does not answer GitHub either: it records an approval that the Prodgator approvers rule can count.

Compliance policies and pull request gates

is a commit status posted on pull requests when you turn on Post the compliance status on pull requests on the Compliance page. Pull request gates report a separate check run, Prodgator Policies, driven by policies bound to pull requests, not to deployment environments. The two do not affect each other: the compliance status keeps checking the compliance policies you turn on, and Prodgator Policies keeps checking the policies you bind to pull requests.

If you want both on the same repository, require both status checks in your branch protection or ruleset: and Prodgator Policies. See status check names.

On this page