When a pull request touches Terraform, Docker, or Kubernetes files, reviews the infrastructure diff for security mistakes such as public storage, open firewall rules, privileged containers, plaintext secrets, over-scoped IAM, and disabled TLS. Posts inline review threads for each finding and a deduplicated summary comment on the pull request.
- Identifier
iac-security-review- Version
- 1.0.0
- Steps
- 4
- Triggers
- 2
- iac
- security
- terraform
- infrastructure
- review
- compliance
When it runs
pull_request.opened- Settle delay
- 15s after the event
Only when all hold
- pullRequest.isDraft not equals true
- actor.username not in dependabot, dependabot[bot], renovate, renovate[bot], github-actions, github-actions[bot]
- actor.username not contains [bot]
pull_request.synchronize- Settle delay
- 15s after the event
Only when all hold
- pullRequest.isDraft not equals true
- actor.username not in dependabot, dependabot[bot], renovate, renovate[bot], github-actions, github-actions[bot]
- actor.username not contains [bot]
The pipeline
The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.
- 01PR Opened / Synchronized
triggerThe event that starts the run.
- 02Clone Repository
git.cloneShallow-clones the repository at the right ref.
- 03Review IaC Security
agent.runOne agent works the task with its toolkit.
- 04Publish Security Summary
report.publishPosts or updates a deduplicated report comment.
The agent
IaC Security Reviewer
- Base type
- Code Reviewer
- Temperature
- 0.2
- Max iterations
- 30
- Tools
- 5
Git provider · 2
get_pull_request_diffGet Pull Request Diff · readadd_pull_request_review_threadAdd PR Review Thread · write
Filesystem · 1
read_fileRead File · read
Code search · 1
code_searchCode Search · read
Status · 1
update_statusUpdate Status · write
Related playbooks
License Compliance Scan
Weekly dependency-tree scan that files one ticket listing every licence violation, review item, or unknown package.
Secret Rotation Reminder
Monthly audit of vault metadata that files a ticket for any credential past its rotation policy, without ever reading a secret value.
Secret & Security Scan
Scans PR diffs for committed secrets — API keys, tokens, private keys — before merge.