← ClaudeAtlas

cloud-cli-safetylisted

Require query-before-modify, full-command display, explicit confirmation, and rollback preparation before any cloud CLI invocation that mutates infrastructure. Covers Azure (`az`), AWS (`aws`), GCP (`gcloud`, `gsutil`), Kubernetes (`kubectl`, `helm`), and Terraform/IaC (`terraform`). Born from a real production incident where a partial-YAML container update wiped every environment variable on a live service.
catpilotai/catpilot-ai-guardrails · ★ 2 · DevOps & Infrastructure · score 78
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline **Applies when:** Before invoking a mutating `az`, `aws`, `gcloud`/`gsutil`, `kubectl`, `helm`, or `terraform` command, or a custom deploy wrapper (`./deploy.sh`, `make deploy`), especially against production-heuristic targets. **Always:** - Query current state (read-only) and show the relevant fields before any mutating command. - Show the full command and affected targets; preserve env/secret references and never expand credentials into chat, logs, or history. - Enumerate fields that will change (env vars, IAM bindings, replica counts, CPU/memory, probes). - Get explicit confirmation (a literal "yes") before executing; do not infer consent. - Prepare a rollback command before executing the forward command. - Know which flags merge and which replace: `az containerapp update --set-env-vars` adds or updates only the named variables and keeps the rest; `--replace-env-vars` and `--yaml` replace the whole set; `aws lambda update-function-configuration --environment` replaces the whole map. - Verify after execution by re-running the read-only query and diffing against the pre-change snapshot. **Never:** - `az containerapp update --yaml <partial>` — overwrites all unspecified fields; `--replace-env-vars` removes unspecified variables too. - `aws lambda update-function-configuration --environment "Variables={ONLY_ONE=value}"` — replaces, does not merge. - `aws s3 rm s3://bucket --recursive` without prior `aws s3 ls` and explicit confirmation. - `gcloud projects set-ia