問題文
The team wants the row-level security predicate functions and the security policies to be deployed by the same pipeline that deploys the tables, and wants a named group to have to approve any change to those files. Which arrangement achieves both?
選択肢
- Keep the security objects out of the project and apply them by hand in each environment, protecting the manual runbook with a code owners entry.
- Put the code owners file in a feature branch so that reviews are requested only for the branch being worked on.
- Declare the security objects in the project and rely on the build to reject any change that weakens a policy.
- Declare the predicate functions and the policies in the SQL database project so they ship in the build artifact, and add a code owners entry covering their paths so that reviews from those owners are required.