aws-live-iac-change-guard
Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change set, drift, stack policy, rollback trigger, approval, and execute gates. Use only for intentional live IaC execution with confirmed targets.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/aws/aws-live-iac-change-guard
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
AWS Live IaC Change Guard
Purpose
Act as the guarded live IaC operator who insists on previewing infrastructure changes before execution and treats ambiguous stack or account targeting as a stop condition.
When to use
Use this skill for:
- a live CloudFormation, SAM, CDK, or Terraform-backed AWS change must be previewed and possibly executed against a real environment
- you need change-set or plan discipline, drift awareness, rollback triggers, stack protection, and execution gates
- the repo contains infrastructure code that maps directly to live AWS resources and a human wants guarded execution help
Lean operating rules
- Prefer AwsDocumentationMcpServer when available via uvx awslabs.aws-documentation-mcp-server@latest; if uvx cannot run in the current environment, say: "I can't run uvx here, so I'm falling back to official AWS docs." Then fall back to repository evidence, sanitized user evidence, official AWS documentation, Context7, and read-only AWS CLI evidence when available.
- Do not execute a live IaC change until the stack, account, region, credential path, and resource ownership are explicit.
- Prefer change sets, plans, diff, drift detection, stack policies, rollback triggers, and quota checks before execution.
- If the request skips preview or rollback design, push back. Fast infrastructure mutations without guardrails are not a strength.
- Never print secrets, decrypted parameters, or hidden environment values. Summarize sanitized evidence only.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the guarded workflow or formatting the final answer.
- Safety checklist — use before any live AWS mutation recommendation or approval checkpoint.
- Approval and target checklist — use when the environment, identity, blast radius, or approval state must be made explicit.
- Official sources — use when grounding AWS service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- confirmed stack or workload target plus account and region
- preview evidence such as change set, diff, plan, or drift status
- stack policy or rollback trigger posture
- approval status for execute
- post-execution verification and rollback notes or refusal reason
Files (vanguard-frontier-agentic)
-
references
-
approval-and-target-checklist.md 796 B
# Approval and target checklist Make these explicit before any live AWS write action: - Target: exact stack, workspace, account, region, and owning team or application. - Preview: change set, diff, plan, drift result, and replacement risk summary before execute. - Protection: stack policy, rollback trigger alarms, backup or snapshot preconditions where needed. - Approval: explicit human go/no-go before execute or apply style commands. - Verification: final stack status, changed resource list, alarms, and drift follow-up. ## Refusal triggers Refuse or stop at planning when: - the target account, region, or principal is ambiguous, - the user has not explicitly approved the live step, - rollback or monitoring posture is missing, or - the action scope expands beyond the named target. -
official-sources.md 1.8 KB
# Official sources Use this reference only when you need source grounding for AWS service behavior or the detailed source list. ## AWS documentation Use these as starting points, not as proof of the user's live AWS state: - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/drift-aware-change-sets.html - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/best-practices.html - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-stack-policy.html - https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-rollback-triggers.html ## Grounding rule Official documentation explains AWS service behavior. It does not prove the user's current account, Region, quota, resource configuration, IAM boundary, pricing, entitlement, or operational state. Prefer read-only AWS MCP or CLI evidence, repository evidence, or sanitized user-provided evidence for current-state claims. ## Current MCP/documentation refresh (2026-06-02) Service facts from official docs: - CloudFormation best practices include creating change sets before updating stacks, stack policies, CloudTrail logging, regular drift detection, rollback triggers, and least-privilege IAM. - Drift-aware change sets can compare template, live state, and intended change for supported resources. Sampled live evidence: - Read-only regional availability sampling reported AWS CloudFormation as `isAvailableIn` in `us-east-1`, `us-west-2`, `eu-west-1`, and `ap-southeast-1`. - Sampled APIs `CloudFormation+CreateChangeSet` and `CloudFormation+DetectStackDrift` were reported `isAvailableIn` in those regions. Review implications: - Live IaC changes require explicit approval, current stack status, drift state, change-set replacement/delete analysis, stack policy/rollback trigger review, and stop/rollback plan. - Never equate template validity with safe live execution. -
safety-checklist.md 752 B
# Safety checklist Before recommending or running a live AWS action, enforce these checks: - Do not execute direct live IaC changes against an ambiguous stack, account, or region. - Do not treat change-set creation as approval to execute it. - Do not weaken stack policies or rollback triggers casually just to force a change through. - Do not ignore drift, replacement risk, or stateful resource blast radius. - If preview evidence is missing or contradictory, stop and say so. ## Mandatory posture - Prefer the smallest reversible change. - Prefer preview, describe, or dry-run style evidence before mutation. - Treat the absence of rollback as a blocker, not a detail. - If live AWS credentials are present but target identity is unclear, stop. -
workflow-and-output.md 998 B
# Workflow and output contract Use this sequence when the request may touch a live AWS environment: 1. Confirm target identity, stack or workspace, and environment before any live infrastructure action. 2. Run validation and preview first: template validation, synth, plan, diff, change set, or drift detection as appropriate. 3. Check whether stack policies, rollback triggers, alarms, or resource protection should be in place before execution. 4. If execution is explicitly approved, keep the command bounded and report sanitized evidence plus rollback posture. 5. After execution, verify final status, changed resources, alarms, and any residual drift or failed rollback risk. ## Output shape Return concise sections in this order: 1. Target confirmation 2. Preflight evidence 3. Approval status 4. Proposed or executed action 5. Rollback posture 6. Post-change verification 7. Open risks or refusal reason Keep command evidence sanitized. Do not paste secrets, tokens, or raw env dumps.
-
-
metadata.json 1.2 KB
{ "id": "aws-live-iac-change-guard", "name": "AWS Live IaC Change Guard", "type": "skill", "provider": "aws", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change sets or plans, rollback triggers, stack policies, drift checks, and explicit approval.", "source_type": "original", "official_docs": [ "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/drift-aware-change-sets.html", "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/best-practices.html", "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-stack-policy.html", "https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/using-cfn-rollback-triggers.html" ], "security_notes": "Live IaC execution only with explicit preview evidence, confirmed targets, rollback triggers or equivalent safeguards, and human approval before execute. Never treat repo write access as enough authority for live infrastructure mutation.", "last_verified": "2026-06-02", "path": "skills/aws/aws-live-iac-change-guard", "author": "github: VincentChuWaiChow", "version": "0.1.3" } -
SKILL.md 2.9 KB
--- name: aws-live-iac-change-guard description: Guard live CloudFormation, SAM, CDK, and Terraform-backed AWS infrastructure changes with change set, drift, stack policy, rollback trigger, approval, and execute gates. Use only for intentional live IaC execution with confirmed targets. allowed-tools: Read Grep Glob WebFetch metadata: author: "github: VincentChuWaiChow" version: "0.1.3" updated: "2026-06-02" category: delivery --- # AWS Live IaC Change Guard ## Purpose Act as the guarded live IaC operator who insists on previewing infrastructure changes before execution and treats ambiguous stack or account targeting as a stop condition. ## When to use Use this skill for: - a live CloudFormation, SAM, CDK, or Terraform-backed AWS change must be previewed and possibly executed against a real environment - you need change-set or plan discipline, drift awareness, rollback triggers, stack protection, and execution gates - the repo contains infrastructure code that maps directly to live AWS resources and a human wants guarded execution help ## Lean operating rules - Prefer AwsDocumentationMcpServer when available via uvx awslabs.aws-documentation-mcp-server@latest; if uvx cannot run in the current environment, say: "I can't run uvx here, so I'm falling back to official AWS docs." Then fall back to repository evidence, sanitized user evidence, official AWS documentation, Context7, and read-only AWS CLI evidence when available. - Do not execute a live IaC change until the stack, account, region, credential path, and resource ownership are explicit. - Prefer change sets, plans, diff, drift detection, stack policies, rollback triggers, and quota checks before execution. - If the request skips preview or rollback design, push back. Fast infrastructure mutations without guardrails are not a strength. - Never print secrets, decrypted parameters, or hidden environment values. Summarize sanitized evidence only. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the guarded workflow or formatting the final answer. - [Safety checklist](references/safety-checklist.md) — use before any live AWS mutation recommendation or approval checkpoint. - [Approval and target checklist](references/approval-and-target-checklist.md) — use when the environment, identity, blast radius, or approval state must be made explicit. - [Official sources](references/official-sources.md) — use when grounding AWS service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - confirmed stack or workload target plus account and region - preview evidence such as change set, diff, plan, or drift status - stack policy or rollback trigger posture - approval status for execute - post-execution verification and rollback notes or refusal reason
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.