e-volv

Security playbook

IaCSecurityReview

Reviews infrastructure PRs for public storage, open firewall rules, privileged containers, plain secrets, and over-broad IAM roles.

When a pull request touches Terraform, Docker, or Kubernetes files, reviews the infrastructure diff for security mistakes such as public storage, open firewall rules, privileged containers, plaintext secrets, over-scoped IAM, and disabled TLS. Posts inline review threads for each finding and a deduplicated summary comment on the pull request.

Identifier
iac-security-review
Version
1.0.0
Steps
4
Triggers
2
  • iac
  • security
  • terraform
  • infrastructure
  • review
  • compliance

When it runs

Pull requestpull_request.opened
Settle delay
15s after the event

Only when all hold

  • pullRequest.isDraft not equals true
  • actor.username not in dependabot, dependabot[bot], renovate, renovate[bot], github-actions, github-actions[bot]
  • actor.username not contains [bot]
Pull requestpull_request.synchronize
Settle delay
15s after the event

Only when all hold

  • pullRequest.isDraft not equals true
  • actor.username not in dependabot, dependabot[bot], renovate, renovate[bot], github-actions, github-actions[bot]
  • actor.username not contains [bot]

The pipeline

The graph below is the one the workflow opens with in the builder — same steps, same layout, drawn on the same canvas. The run playing through it is a simulation; the branches and conditions are real.

  1. 01
    PR Opened / Synchronizedtrigger

    The event that starts the run.

  2. 02
    Clone Repositorygit.clone

    Shallow-clones the repository at the right ref.

  3. 03
    Review IaC Securityagent.run

    One agent works the task with its toolkit.

  4. 04
    Publish Security Summaryreport.publish

    Posts or updates a deduplicated report comment.

The agent

IaC Security Reviewer

Base type
Code Reviewer
Temperature
0.2
Max iterations
30
Tools
5

Git provider · 2

  • get_pull_request_diffGet Pull Request Diff · read
  • add_pull_request_review_threadAdd PR Review Thread · write

Filesystem · 1

  • read_fileRead File · read

Code search · 1

  • code_searchCode Search · read

Status · 1

  • update_statusUpdate Status · write