<ul data-eligibleForWebStory="false">Experimenting with Spacelift's policies to enforce guardrails in AWS infrastructure using Rego.Challenges in writing Rego policies from scratch to allow/deny specific EC2 instances.Documenting failures and learning experiences while implementing and customizing policies in Spacelift.Lessons learned from mastering Rego, clear policy messages, and balancing freedom with control.