Review evidence

pulumi/docs PR #21431 c544e7499d generated 2026-09-20T12:30:05Z

Verification trail

#2 ✅ Verified
content/blog/day-2-operations-drift-detection-and-remediation/index.md:81
Pulumi's policy packs feature acts as guardrails that block misconfigurations before they can cause damage.
evidence: The policy docs page states policies "enforce guardrails that prevent common misconfigurations" and that preventative enforcement "Validates Pulumi stack resources during pulumi preview and pulumi up, blocking deployments when violations…; source: repo:content/docs/discovery-governance/policy/_index.md
source: repo:content/docs/discovery-governance/policy/_index.md
framing: exact-match
pass1 · url · high confidence
#4 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:57
With Pulumi Policies, users can write policies in TypeScript instead of maintaining policy documents in wikis or relying on manual reviews.
evidence: The Pulumi Policies docs page states: "You write policies in programming languages and manage them alongside your infrastructure code, instead of manually configuring compliance rules through cloud provider consoles or maintaining policy…; source: repo:content/docs/discovery-governance/policy/_index.md
source: repo:content/docs/discovery-governance/policy/_index.md
framing: exact-match
pass1 · url · high confidence
#5 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:59
The TypeScript policy-pack authoring documentation is located at /docs/discovery-governance/policy/policy-packs/authoring/#creating-a-policy-pack.
evidence: The pulumi/docs source file content/docs/discovery-governance/policy/policy-packs/authoring.md (URL /docs/discovery-governance/policy/policy-packs/authoring/) contains the H2 heading "## Creating a policy pack" (anchor…; source: gh api repos/pulumi/docs/contents/content/docs/discovery-governance/policy/policy-packs/authoring.md
source: gh api repos/pulumi/docs/contents/content/docs/discovery-governance/policy/policy-packs/authoring.md
framing: exact-match
pass1 · cross-reference · high confidence
#6 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:63
Pulumi Policies supports two fundamental types of policies, each serving different validation needs.
evidence: Pulumi's official blog and docs confirm there are two core policy types: "ResourceValidationPolicy - Validates a particular resource in a stack. StackValidationPolicy - Validates the stack as a whole," each used for different validation…; source: https://www.pulumi.com/blog/enforcing-different-kinds-of-policies-for-cloud-resources/
source: https://www.pulumi.com/blog/enforcing-different-kinds-of-policies-for-cloud-resources/
framing: exact-match
pass3 · numerical · high confidence
#7 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:65
The Resource Policies documentation is located at /docs/discovery-governance/policy/policy-packs/authoring/#resource-validation-policies.
evidence: The authoring.md doc file (served at /docs/discovery-governance/policy/policy-packs/authoring/) contains a heading '### Resource validation policies' which Hugo slugifies to the anchor #resource-validation-policies, matching the claimed…; source: repo:content/docs/discovery-governance/policy/policy-packs/authoring.md (line 353: "### Resource validation policies")
source: repo:content/docs/discovery-governance/policy/policy-packs/authoring.md (line 353: "### Resource validation policies")
framing: exact-match
pass1 · cross-reference · high confidence
#8 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:199
The Pulumi Policies enforcement-modes documentation is located at /docs/discovery-governance/policy/#enforcement-modes.
evidence: The page content/docs/discovery-governance/policy/_index.md contains a heading "### Enforcement modes" (line 59) under the path /docs/discovery-governance/policy/, which Hugo will render with anchor #enforcement-modes, matching the cited…; source: repo:content/docs/discovery-governance/policy/_index.md (line 59: "### Enforcement modes")
source: repo:content/docs/discovery-governance/policy/_index.md (line 59: "### Enforcement modes")
framing: exact-match
pass1 · url · high confidence
#10 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:394
Complete policy examples are provided at https://github.com/pulumi/workshops/tree/main/idp-component-policies/demo-policies.
evidence: The GitHub path pulumi/workshops/tree/main/idp-component-policies/demo-policies exists and contains policy example files including PulumiPolicy.yaml, __main__.py, and demo-policies-typescript-example.ts, matching the claim that complete…; source: gh api repos/pulumi/workshops/contents/idp-component-policies/demo-policies
source: gh api repos/pulumi/workshops/contents/idp-component-policies/demo-policies
framing: exact-match
pass1 · cross-reference · high confidence
#11 ✅ Verified
content/blog/deployment-guardrails-with-policy-as-code/index.md:394
A compliance-ready policy catalog addressing specific regulatory requirements is located at /docs/discovery-governance/policy/policy-packs/pre-built-packs/.
evidence: The page content/docs/discovery-governance/policy/policy-packs/pre-built-packs.md exists in pulumi/docs and describes pre-built compliance policy packs (CIS, PCI DSS, HITRUST, NIST, ISO 27001, CMMC). Its sibling page states: '**Pre-built…; source: gh search code --owner pulumi pre-built-packs (content/docs/discovery-governance/policy/policy-packs/pre-built-packs.md and policy-packs/_index.md)
source: gh search code --owner pulumi pre-built-packs (content/docs/discovery-governance/policy/policy-packs/pre-built-packs.md and policy-packs/_index.md)
framing: exact-match
pass1 · cross-reference · high confidence
#12 ✅ Verified
content/blog/idp-strategy-planning-self-service-infrastructure-that-balances-developer-autonomy-with-operational-control/index.md:215
Policy-as-code guardrails run automatically and prevent policy violations before deployment happens, giving developers immediate feedback and assurance that…
evidence: Pulumi's own Policies docs confirm this exact behavior: "Preventative: Validates Pulumi stack resources during pulumi preview and pulumi up, blocking deployments when violations are detected. Prevents non-compliant resources from being…; source: repo:content/docs/discovery-governance/policy/_index.md
source: repo:content/docs/discovery-governance/policy/_index.md
framing: exact-match
pass1 · behavior · high confidence
#13 ✅ Verified
content/blog/idp-strategy-planning-self-service-infrastructure-that-balances-developer-autonomy-with-operational-control/index.md:216
The described guardrail safety net is policy-as-code that runs automatically, preventing violations before deployment happens.
evidence: Pulumi Policy docs confirm this: "Preventative: Validates Pulumi stack resources during pulumi preview and pulumi up, blocking deployments when violations are detected. Prevents non-compliant resources from being created." This matches…; source: repo:content/docs/discovery-governance/policy/_index.md
source: repo:content/docs/discovery-governance/policy/_index.md
framing: exact-match
pass1 · behavior · high confidence
#15 ✅ Verified
content/blog/idp-strategy-planning-self-service-infrastructure-that-balances-developer-autonomy-with-operational-control/index.md:218
With this policy-as-code approach, the developer gets immediate feedback when a violation occurs.
framing: Source shows the CLI/engine displays policy violations synchronously during preview/up; claim's "immediate feedback" is a narrower, accurate restatement of…; evidence: Pulumi's engine emits PolicyEvents during preview/up and the CLI displays policy violations inline in the deployment output (pkg/backend/display/progress.go: "Always show row if there's a policy violation event... Policy violations…; source: gh search code --owner pulumi "policy violation" (pulumi/pulumi: pkg/backend/display/progress.go, pkg/resource/deploy/step_generator.go)
source: gh search code --owner pulumi "policy violation" (pulumi/pulumi: pkg/backend/display/progress.go, pkg/resource/deploy/step_generator.go)
framing: entailed-narrower — Source shows the CLI/engine displays policy violations synchronously during preview/up; claim's "immediate feedback" is a narrower, accurate restatement of this behavior.
pass1 · behavior · high confidence
#1 ➖ Not a claim
content/blog/day-2-operations-drift-detection-and-remediation/index.md:81
Standardized components encode best practices, making it easier to do the right thing than the wrong thing.
evidence: This is a general editorial/opinion statement about the benefits of standardized components (a best-practice design philosophy), not a falsifiable technical claim about a specific Pulumi feature, API, or number that could be checked…; source: content/blog/day-2-operations-drift-detection-and-remediation/index.md (L81)
source: content/blog/day-2-operations-drift-detection-and-remediation/index.md (L81)
pass1 · feature · high confidence
#3 ➖ Not a claim
content/blog/deployment-guardrails-with-policy-as-code/index.md:7
The blog post's conclusion references Statsig's transformation and a technical deep-dive into Pulumi Policies as illustrating that the speed-versus-safety…
evidence: Line 386 reads: "We started this post with a fundamental tension in platform engineering: the need for both speed and safety. Through the lens of Statsig's transformation and the technical deep-dive into Pulumi Policies, we've seen that…; source: repo:content/blog/deployment-guardrails-with-policy-as-code/index.md
source: repo:content/blog/deployment-guardrails-with-policy-as-code/index.md
pass1 · url · high confidence
#9 ➖ Not a claim
content/blog/deployment-guardrails-with-policy-as-code/index.md:386
Statsig underwent a transformation involving Pulumi Policies, as discussed earlier in the post.
evidence: The claim is a self-referential narrative statement about the blog post's own structure ("as discussed earlier in the post"), pointing back to the Statsig case study discussed earlier in the same article. The source itself confirms this…; source: https://www.pulumi.com/blog/deployment-guardrails-with-policy-as-code/
source: https://www.pulumi.com/blog/deployment-guardrails-with-policy-as-code/
pass3 · entity-spec · high confidence
#14 🤷 Unverifiable
content/blog/idp-strategy-planning-self-service-infrastructure-that-balances-developer-autonomy-with-operational-control/index.md:217
When Pulumi works with customers on implementing Pulumi Policies, they embed security, compliance, and cost controls directly into the deployment process…
framing: shifted — source describes what Pulumi Policies as a product does; claim frames it as a narrative about Pulumi's customer engagements, which the docs page…; evidence: The docs page confirms Pulumi Policies' capabilities align with the claim's substance ("Cost control... Compliance and security... Enforce guardrails that prevent common misconfigurations"), but the claim's specific framing — "When…; source: content/docs/discovery-governance/policy/_index.md
source: content/docs/discovery-governance/policy/_index.md
framing: shifted — shifted — source describes what Pulumi Policies as a product does; claim frames it as a narrative about Pulumi's customer engagements, which the docs page doesn't speak to.
pass1 · attribution · medium confidence

Findings

IDBucketFile:linesStatusDisposition
F2 ⚠️ Reviewer check content/blog/deployment-guardrails-with-policy-as-code/index.md:390 open —

Editorial stances

The extractor found no positioning or comparison language in this PR's added lines.

Investigation log

cross-sibling-reads
not run (not in a templated section)
external-claim-verification
11 of 15 claims verified (1 unverifiable, 0 contradicted) · 4 specialists (numerical, cross-reference, capability, framing); 0 cross-specialist corroborations · routed: 0 inline, 13 Pass 1, 0 Pass 2, 2 Pass 3 (verified 1, contradicted 0, unverifiable 1).
cited-claim-spot-checks
not run (no cited claims)
frontmatter-sweep
ran on body + meta_desc + social.{linkedin, twitter}
temporal-trigger-sweep
ran (recency words present in diff; spot-check in-review)
code-execution
not run (no `static/programs/` change)
code-examples-checks
not run (no fenced code blocks in content files)
editorial-balance-pass
ran (single-subject, N/A)

Editorial balance

{
  "files": [
    {
      "file": "content/blog/day-2-operations-drift-detection-and-remediation/index.md",
      "outliers": [
        {
          "heading": "Pulumi's Drift Detection and Remediation Workflow",
          "lines": 35,
          "ratio": 5.0
        },
        {
          "heading": "Handling Common Drift Scenarios",
          "lines": 44,
          "ratio": 6.3
        }
      ],
      "sections": [
        {
          "heading": "The Reality of Infrastructure Drift",
          "lines": 3
        },
        {
          "heading": "Understanding the Prevention vs. Detection Paradigm",
          "lines": 8
        },
        {
          "heading": "What Is Infrastructure Drift?",
          "lines": 4
        },
        {
          "heading": "Pulumi's Drift Detection and Remediation Workflow",
          "lines": 35
        },
        {
          "heading": "Automating Drift Detection with Pulumi Deployments",
          "lines": 20
        },
        {
          "heading": "Handling Common Drift Scenarios",
          "lines": 44
        },
        {
          "heading": "The Value of Automated Drift Detection",
          "lines": 6
        },
        {
          "heading": "Getting Started with Drift Detection",
          "lines": 7
        },
        {
          "heading": "Conclusion: Day 2 Operations as a Competitive Advantage",
          "lines": 7
        }
      ],
      "stats": {
        "mean": 14.9,
        "median": 7,
        "std": 14.1
      },
      "threshold_flags": [
        {
          "heading": "Pulumi's Drift Detection and Remediation Workflow",
          "lines": 35,
          "ratio": 5.0,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Handling Common Drift Scenarios",
          "lines": 44,
          "ratio": 6.3,
          "type": "section-depth-3x-median"
        }
      ]
    },
    {
      "file": "content/blog/deployment-guardrails-with-policy-as-code/index.md",
      "outliers": [
        {
          "heading": "Introducing Pulumi Policies: Policy as Code",
          "lines": 28,
          "ratio": 6.2
        },
        {
          "heading": "Building Practical Guardrails: Real-World Examples",
          "lines": 78,
          "ratio": 17.3
        },
        {
          "heading": "Policy Enforcement Models",
          "lines": 22,
          "ratio": 4.9
        },
        {
          "heading": "Policy Remediation: Beyond Detection",
          "lines": 20,
          "ratio": 4.4
        },
        {
          "heading": "Compliance-Ready Policies",
          "lines": 20,
          "ratio": 4.4
        },
        {
          "heading": "Best Practices for Policy Implementation",
          "lines": 29,
          "ratio": 6.4
        }
      ],
      "sections": [
        {
          "heading": "The Platform Engineering Challenge: Speed vs. Safety",
          "lines": 3
        },
        {
          "heading": "Understanding Platform Engineering Layers",
          "lines": 4
        },
        {
          "heading": "What Are Deployment Guardrails?",
          "lines": 2
        },
        {
          "heading": "Introducing Pulumi Policies: Policy as Code",
          "lines": 28
        },
        {
          "heading": "Building Practical Guardrails: Real-World Examples",
          "lines": 78
        },
        {
          "heading": "Policy Enforcement Models",
          "lines": 22
        },
        {
          "heading": "Policy Remediation: Beyond Detection",
          "lines": 20
        },
        {
          "heading": "Server-Side Policy Enforcement",
          "lines": 1
        },
        {
          "heading": "Compliance-Ready Policies",
          "lines": 20
        },
        {
          "heading": "Best Practices for Policy Implementation",
          "lines": 29
        },
        {
          "heading": "Real-World Success: Statsig's Transformation",
          "lines": 4
        },
        {
          "heading": "Building Your Policy Strategy",
          "lines": 4
        },
        {
          "heading": "Measuring Policy Success",
          "lines": 4
        },
        {
          "heading": "Common Pitfalls and How to Avoid Them",
          "lines": 5
        },
        {
          "heading": "The Future of Policy as Code",
          "lines": 4
        },
        {
          "heading": "Conclusion: Enabling Safe Self-Service at Scale",
          "lines": 8
        }
      ],
      "stats": {
        "mean": 14.8,
        "median": 4.5,
        "std": 18.9
      },
      "threshold_flags": [
        {
          "heading": "Introducing Pulumi Policies: Policy as Code",
          "lines": 28,
          "ratio": 6.2,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Building Practical Guardrails: Real-World Examples",
          "lines": 78,
          "ratio": 17.3,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Policy Enforcement Models",
          "lines": 22,
          "ratio": 4.9,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Policy Remediation: Beyond Detection",
          "lines": 20,
          "ratio": 4.4,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Compliance-Ready Policies",
          "lines": 20,
          "ratio": 4.4,
          "type": "section-depth-3x-median"
        },
        {
          "heading": "Best Practices for Policy Implementation",
          "lines": 29,
          "ratio": 6.4,
          "type": "section-depth-3x-median"
        }
      ]
    },
    {
      "file": "content/blog/idp-strategy-planning-self-service-infrastructure-that-balances-developer-autonomy-with-operational-control/index.md",
      "outliers": [],
      "sections": [
        {
          "heading": "Understanding the Platform Engineering Layers in Your Internal Developer Platform",
          "lines": 30
        },
        {
          "heading": "IDP Example: Building a Web Application Platform Step-by-Step",
          "lines": 24
        },
        {
          "heading": "Why Internal Developer Platforms Matter in 2025 and Beyond",
          "lines": 5
        },
        {
          "heading": "5 Core Components of a Successful Internal Developer Platform",
          "lines": 40
        },
        {
          "heading": "How to Implement Your IDP Strategy",
          "lines": 22
        },
        {
          "heading": "How to Measure the Success of Your Internal Developer Platform",
          "lines": 10
        },
        {
          "heading": "IDP Strategy: 5 Key Steps to Build a Strong Foundation",
          "lines": 11
        },
        {
          "heading": "The Future of IDPs and Platform Engineering",
          "lines": 13
        }
      ],
      "stats": {
        "mean": 19.4,
        "median": 17.5,
        "std": 11.0
      },
      "threshold_flags": []
    }
  ],
  "trigger": null
}

Triaged

History

  1. 2026-09-20T12:30:05Z c544e74

    initial review (pending publication)