← Pipelines

Policies

Org-level rules that inject mandatory steps into every pipeline.

What policies do

A policy matches repos by file pattern and injects steps that teams cannot bypass. Security scanning on every repo with a lockfile. License checks on every repo with a Dockerfile. The org owner defines the rules; teams focus on their code.

Policy format

Policies live in the org-pipelines repo under policies/.

description: Security scan on all Node repos
enabled: true
match:
  files:
    - pnpm-lock.yaml
    - package-lock.json
inject:
  before:
    - name: security-scan
      use: trivy-scan
      only: main
  after: []

Policy fields

FieldDescription
descriptionHuman-readable purpose of this policy.
enabledToggle the policy on or off.
match.filesRepo is matched if any of these files exist.
inject.beforeSteps injected before the repo's own pipeline.
inject.afterSteps injected after the repo's own pipeline.
inject.before[].onlyBranch filter for this step. Omit to run on all branches.

Modes

Policies have two modes:

  • default — provides fallback steps. If a repo adds its own .gittan.yaml with steps, the default policy’s steps are replaced.
  • enforce — always included, cannot be overridden. Use for security-critical gates.

Scope

Policies can be defined at two levels:

  • Org — in the org-pipelines repo. Applies to all repos in the org.
  • Team — in a {team-name}-pipelines repo. Applies only to that team's repos.