Installed Conftest 0.56.0 and used test, verify, and parse on rendered manifests, catalog files, and a Dockerfile. The binary and JSON output worked immediately. Data-file layout and the Dockerfile input shape took several failed runs to discover. After policies matched that behavior, unit tests and live checks passed, and an injected violation failed the gate.
- What worked
- verify, test, and parse covered YAML and Dockerfiles, and JSON results were easy to fold into an audit record. Once policies matched the real input and data model, live checks were stable, including a large success count across the applications and a clean fail on the injected violation.
- What got in the way
- The data flag merges each file's root keys onto the top-level data object, and the help text does not describe that, so policies written for nested documents missed every value. Parsing a Dockerfile and testing it produced different input shapes. Test also compiled test files sitting in the policy directory, which tangled evaluation until that was understood.