<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Governance on TCS Labs Academy</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/categories/governance/</link><description>Recent content in Governance on TCS Labs Academy</description><generator>Hugo</generator><language>en</language><atom:link href="https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/categories/governance/index.xml" rel="self" type="application/rss+xml"/><item><title>1. Policy as Code with Meshery</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/policy-as-code-with-meshery/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/policy-as-code-with-meshery/</guid><description>&lt;p&gt;Platform engineers operating at scale cannot rely on manual review to enforce infrastructure standards. Meshery addresses this by treating policy as code - encoding governance rules directly into the platform through relationships, OPA constraints, and environment-specific policy gates.&lt;/p&gt;
&lt;p&gt;This course covers how Meshery&amp;rsquo;s relationship model acts as executable policy, how Open Policy Agent integrates with Meshery to express constraints as code, and how to validate designs - including those produced by a coding agent - before they reach a live cluster. You will also learn to promote designs through environments with graduated policy strictness, ensuring only conformant configurations reach production.&lt;/p&gt;</description></item><item><title>Compliance</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/compliance-and-evidence/compliance/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/compliance-and-evidence/compliance/</guid><description/></item><item><title>Policy</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/policy-as-code-with-meshery/policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/policy-as-code-with-meshery/policy/</guid><description/></item><item><title>Responsible AI</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/responsible-ai-for-operations/responsible-ai/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/responsible-ai-for-operations/responsible-ai/</guid><description/></item><item><title>Secure</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/securing-ai-driven-pipelines/secure/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/securing-ai-driven-pipelines/secure/</guid><description/></item><item><title>2. Securing AI-Driven Pipelines</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/securing-ai-driven-pipelines/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/securing-ai-driven-pipelines/</guid><description>&lt;p&gt;AI-driven pipelines introduce a new class of infrastructure actor: an autonomous agent that reads context, generates manifests, and applies changes to live clusters. That power demands a matching security discipline. A misconfigured agent can leak credentials, apply unreviewed code, or grant itself elevated permissions - at machine speed, without a human in the loop.&lt;/p&gt;
&lt;p&gt;This course walks through the four pillars of secure agent pipelines: managing secrets safely so they never appear in prompts or generated designs; verifying the provenance and integrity of AI-generated manifests and images before trust is granted; isolating agent workloads so a compromise cannot spread; and designing minimal, auditable permissions for every automated identity. Each lesson provides concrete patterns you can apply immediately when operating Meshery and Kanvas in production.&lt;/p&gt;</description></item><item><title>3. Responsible AI for Operations</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/responsible-ai-for-operations/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/responsible-ai-for-operations/</guid><description>&lt;p&gt;AI agents can propose, generate, and apply infrastructure changes at a speed and scale that outpaces traditional review. That capability is only safe when it is surrounded by deliberate controls - validation layers that catch hallucinated resources before they reach a cluster, audit trails that record every proposal and its rationale, cost budgets that prevent runaway token and cloud spend, and clear human ownership that ensures someone is always accountable for what the agent does.&lt;/p&gt;</description></item><item><title>4. Compliance &amp; Evidence</title><link>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/compliance-and-evidence/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://meshery-extensions.github.io/tcslabs-academy/pr-preview/pr-36/learning-paths/deea6061-b6be-49a9-ad1c-f1a5c32e1fa9/governance-security-and-responsible-ai-for-infrastructure/compliance-and-evidence/</guid><description>&lt;p&gt;Compliance in a modern Internal Developer Platform is not a periodic audit - it is a continuous property of the system. When coding agents propose and deploy infrastructure changes at machine speed, the compliance posture must be verifiable at every step, not reconstructed after the fact.&lt;/p&gt;
&lt;p&gt;This course establishes how compliance works inside an IDP powered by Meshery and AI-driven automation. You will learn how to map regulatory and organizational controls to platform capabilities, produce durable attestations from Git history and Meshery activity, detect drift between intended and actual state using MeshSync, and run continuous checks that keep the platform permanently audit-ready.&lt;/p&gt;</description></item></channel></rss>