Skip to content

[codex] add prod-like Terraform sandbox design#37

Merged
InfoSecHack merged 1 commit into
mainfrom
codex/prod-like-terraform-sandbox-design
Jun 4, 2026
Merged

[codex] add prod-like Terraform sandbox design#37
InfoSecHack merged 1 commit into
mainfrom
codex/prod-like-terraform-sandbox-design

Conversation

@InfoSecHack
Copy link
Copy Markdown
Owner

Summary

  • Add the Phase 3 Terraform sandbox design for the prod-like AWS accuracy benchmark.
  • Map the frozen 24-row oracle fixture to future Terraform resource groups without expanding scope.
  • Define dedicated sandbox account policy, future module layout, max v1 limits, optional live probe categories, collection/cleanup plans, gates, and non-claims.

Boundaries

  • Docs/spec only.
  • No Terraform files, tests, code, runner changes, live AWS, AWS CLI, STS/Lambda/API calls, iam:PassRole calls, Terraform init/plan/apply/destroy, reasoner changes, benchmark semantic changes, release/version change, or new evidence claims.
  • No composite benchmark score or pass/fail benchmark label.

Validation

  • design grep for fixture id, Terraform path, dedicated sandbox/account guard/ack, max v1 limits, live probe boundary, gates, non-claims, and next slice
  • account/ARN hygiene scans
  • generated live/Terraform artifact scan
  • ./scripts/check.sh
  • ./scripts/test_fast.sh
  • git diff --check

@InfoSecHack InfoSecHack marked this pull request as ready for review June 4, 2026 04:52
@InfoSecHack InfoSecHack merged commit b393a37 into main Jun 4, 2026
6 checks passed
@InfoSecHack InfoSecHack deleted the codex/prod-like-terraform-sandbox-design branch June 4, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant