IaC Review
Ortak Doktrin
agents/shared/severity-rubric.md ve agents/shared/escalation-matrix.md default-load
sayılır (agents/coordination.md §11). Bu skill'in çıktısı Critical / High / Medium /
Low + kanıt formatında olmak zorunda — spekülatif Critical yasak. Sahiplik dışı bulgu
ilgili agent'a delege; karar yetkisi eşiği aşılırsa kullanıcı onayı zorunlu.
Ne Zaman Kullanılır
- IaC PR review (yeni resource / değişiklik)
- Yeni module yazımı
- State migration planı
- Drift detection alarm
- Security scan bulgu inceleme (tfsec/checkov)
- Multi-env refactor
- Cost engineering
Workflow
1) Tool tespit
| Tool |
İşaret |
| Terraform |
*.tf, terraform.tfstate*, .terraform.lock.hcl |
| Pulumi |
Pulumi.yaml, Pulumi.<stack>.yaml |
| CloudFormation |
*.yaml/*.json AWSTemplateFormatVersion |
| Ansible |
playbook.yml, inventory/, roles/ |
| AWS CDK |
cdk.json, bin/, lib/*.ts |
2) State management review
- Remote backend mu? Local state fail.
- Locking (DynamoDB / GCS object lock).
- Encryption at rest (KMS / SSE-S3).
- Versioning açık (state geri alma için).
- Per-env ayrı state (dev/staging/prod karışmıyor).
- Workspace vs directory — directory tercih (clarity).
3) Module contract review
variables.tf input + outputs.tf output explicit.
versions.tf Terraform + provider versiyonu pin.
variable validation block (tip + range + regex).
default değer verilirken comment.
- Module source
?ref=v1.2.0 semver pin (mutable ref yasak).
4) Plan output review
PR description'da terraform plan zorunlu:
Plan: 3 to add, 1 to change, 0 to destroy.
to destroy > 0 → highlight + 2-person review.
prevent_destroy = false ihlali → block.
- Sensitive resource (DB, KMS, prod K8s) → ek onay.
- Provider/region değişimi → state migration ayrı PR.
5) Resource hijyeni
- Naming:
<env>-<service>-<purpose> convention.
- Tag/label zorunlu: Environment, Service, ManagedBy, Owner, CostCenter.
- Lifecycle:
prevent_destroy = true DB/KMS/VPC.
create_before_destroy = true zero-downtime.
ignore_changes minimum (drift kaynağı).
for_each > count (stable address).
- Provider alias multi-region explicit.
6) Secret review
- State'te plaintext:
random_password, local_file → state encryption şart.
*.tfvars Git'te: terraform.tfvars .gitignore'da olmalı; sample
terraform.tfvars.example OK.
TF_VAR_* ENV preferred runtime için.
- Vault provider secret reference; plaintext yok.
- CI'da OIDC federation (AWS / GCP); long-lived access key yok.
7) Security scan
| Tool |
Kapsam |
| tfsec |
TF-specific, hızlı, CIS/HIPAA/PCI rule set |
| checkov |
Multi-IaC, geniş policy (1k+ check) |
| kics |
Multi-IaC, KICS query language |
| OPA + Conftest |
Custom policy (organization-specific) |
| Sentinel |
TF Cloud paid, policy-as-code |
Severity threshold:
- Critical → block PR (örn. public S3 bucket, security group
0.0.0.0/0 to all ports).
- High → review + plan eklenir.
- Medium → ticket, follow-up.
8) Drift detection
terraform plan cron (haftalık) — drift varsa alert.
- AWS Config / GCP Asset Inventory — gerçek state karşılaştırma.
- Drift sebepleri:
- Console click (insan).
- Auto-scaling / managed service değişimi (beklenen).
- 3rd party tool (Crossplane, Operator).
- Reconcile: state'e adapte (
terraform import / state mv) veya
config'e ekle (ignore_changes precise).
9) Cost diff (Infracost)
- PR comment:
Δ cost / month.
> $100/ay artış → review + justification.
- Idle resource detection (gauge unused).
10) Module test
- terratest (Go) — apply + assert + destroy.
terraform test (1.6+) — declarative.
- Kitchen-terraform (Ruby).
- Ayrı test AWS account / GCP project — prod'a bulaşma yok.
Checklist
Antipattern
- Local state.
master/main ref module source.
-auto-approve rutin.
- State manuel
rm/mv review'sız.
- Cross-env tek state.
*.tfvars secret Git'te.
count = enabled ? 1 : 0 boolean toggle.
provisioner "local-exec" rutin.
null_resource + local-exec state-driven olmayan.
ignore_changes = all.
-target apply rutin.
- Console click prod'da.
- Module versiyon
latest prod'da.
- Plan output review yok.
Örnek Agent Davranışı
User: /iac-review terraform/envs/prod/
Agent (iac-engineer):
1. Tool tespit: Terraform 1.6.4, AWS provider 5.x.
2. State: S3 backend + DynamoDB lock ✓; encryption KMS ✓; versioning ✓.
3. Module contract: 3 modül; `vpc` `master` ref kullanıyor (Critical, mutable).
4. Plan output:
- Plan: 7 to add, 2 to change, 1 to destroy.
- destroy: aws_db_instance.legacy → `prevent_destroy = false` (Critical).
5. Tag eksik: 4 resource'ta `CostCenter` yok (Medium).
6. Secret: `terraform.tfvars` `.gitignore`'da var ✓; `TF_VAR_DB_PASSWORD` CI ENV.
7. Security: tfsec 3 finding (1 High public S3 ACL, 2 Medium SG egress).
8. Cost: Infracost +$340/ay → RDS instance class büyütüldü.
9. Output:
- Critical: vpc module ref pin + DB prevent_destroy + S3 ACL
- High: SG egress
- Medium: tag eksik 4 resource
- 8 issue açıldı (sahip + tarih).
Çıktı Formatı
# IaC Review: <path>
## State / Backend
- Remote, locking, encryption, versioning, per-env
## Module Contract
- variables / outputs / versions / source pin
## Plan Output
```text
Plan: ... to add, ... to change, ... to destroy
Critical / High / Medium / Low
Security Scan
- tfsec / checkov / OPA özet
Cost Diff (Infracost)
Action Items
| Öncelik | Aksiyon | Sahip | Bitiş | Issue |
1---2name: iac-review3description: Terraform / Pulumi / CloudFormation review — state management, module contract, plan output, drift detection, security scan (tfsec/checkov/OPA), cost diff (Infracost). Plan ≠ apply disiplini.4---56# IaC Review78## Ortak Doktrin910`agents/shared/severity-rubric.md` ve `agents/shared/escalation-matrix.md` default-load11sayılır (`agents/coordination.md` §11). Bu skill'in çıktısı **Critical / High / Medium /12Low + kanıt** formatında olmak zorunda — spekülatif Critical yasak. Sahiplik dışı bulgu13ilgili agent'a delege; karar yetkisi eşiği aşılırsa **kullanıcı onayı zorunlu**.1415## Ne Zaman Kullanılır16- IaC PR review (yeni resource / değişiklik)17- Yeni module yazımı18- State migration planı19- Drift detection alarm20- Security scan bulgu inceleme (tfsec/checkov)21- Multi-env refactor22- Cost engineering2324## Workflow2526### 1) Tool tespit27| Tool | İşaret |28|---|---|29| Terraform | `*.tf`, `terraform.tfstate*`, `.terraform.lock.hcl` |30| Pulumi | `Pulumi.yaml`, `Pulumi.<stack>.yaml` |31| CloudFormation | `*.yaml`/`*.json` `AWSTemplateFormatVersion` |32| Ansible | `playbook.yml`, `inventory/`, `roles/` |33| AWS CDK | `cdk.json`, `bin/`, `lib/*.ts` |3435### 2) State management review36- **Remote backend** mu? Local state **fail**.37- **Locking** (DynamoDB / GCS object lock).38- **Encryption at rest** (KMS / SSE-S3).39- **Versioning** açık (state geri alma için).40- **Per-env ayrı state** (dev/staging/prod karışmıyor).41- **Workspace vs directory** — directory tercih (clarity).4243### 3) Module contract review44- `variables.tf` input + `outputs.tf` output explicit.45- `versions.tf` Terraform + provider versiyonu pin.46- `variable` validation block (tip + range + regex).47- `default` değer verilirken comment.48- Module source `?ref=v1.2.0` semver pin (mutable ref yasak).4950### 4) Plan output review51PR description'da `terraform plan` zorunlu:52```text53Plan: 3 to add, 1 to change, 0 to destroy.54```5556- **`to destroy > 0`** → highlight + 2-person review.57- **`prevent_destroy = false` ihlali** → block.58- **Sensitive resource** (DB, KMS, prod K8s) → ek onay.59- **Provider/region değişimi** → state migration ayrı PR.6061### 5) Resource hijyeni62- **Naming**: `<env>-<service>-<purpose>` convention.63- **Tag/label** zorunlu: Environment, Service, ManagedBy, Owner, CostCenter.64- **Lifecycle**:65 - `prevent_destroy = true` DB/KMS/VPC.66 - `create_before_destroy = true` zero-downtime.67 - `ignore_changes` minimum (drift kaynağı).68- **`for_each` > `count`** (stable address).69- **Provider alias** multi-region explicit.7071### 6) Secret review72- **State'te plaintext**: `random_password`, `local_file` → state encryption şart.73- **`*.tfvars` Git'te**: `terraform.tfvars` `.gitignore`'da olmalı; sample74 `terraform.tfvars.example` OK.75- **`TF_VAR_*`** ENV preferred runtime için.76- **Vault provider** secret reference; plaintext yok.77- **CI'da OIDC federation** (AWS / GCP); long-lived access key yok.7879### 7) Security scan80| Tool | Kapsam |81|---|---|82| **tfsec** | TF-specific, hızlı, CIS/HIPAA/PCI rule set |83| **checkov** | Multi-IaC, geniş policy (1k+ check) |84| **kics** | Multi-IaC, KICS query language |85| **OPA + Conftest** | Custom policy (organization-specific) |86| **Sentinel** | TF Cloud paid, policy-as-code |8788Severity threshold:89- **Critical** → block PR (örn. public S3 bucket, security group `0.0.0.0/0` to all ports).90- **High** → review + plan eklenir.91- **Medium** → ticket, follow-up.9293### 8) Drift detection94- **`terraform plan` cron** (haftalık) — drift varsa alert.95- **AWS Config / GCP Asset Inventory** — gerçek state karşılaştırma.96- **Drift sebepleri**:97 - Console click (insan).98 - Auto-scaling / managed service değişimi (beklenen).99 - 3rd party tool (Crossplane, Operator).100- **Reconcile**: state'e adapte (`terraform import` / `state mv`) veya101 config'e ekle (`ignore_changes` precise).102103### 9) Cost diff (Infracost)104- PR comment: `Δ cost / month`.105- `> $100/ay` artış → review + justification.106- Idle resource detection (gauge unused).107108### 10) Module test109- **terratest** (Go) — apply + assert + destroy.110- **`terraform test`** (1.6+) — declarative.111- **Kitchen-terraform** (Ruby).112- Ayrı test AWS account / GCP project — prod'a bulaşma yok.113114## Checklist115- [ ] Remote backend + locking + encryption + versioning116- [ ] Per-env ayrı state117- [ ] Module contract (variables/outputs/versions)118- [ ] Module source semver pin (`?ref=v1.2.0`)119- [ ] Plan output PR'a yapışık120- [ ] `to destroy` highlight + onay121- [ ] Tag/label zorunlu122- [ ] `prevent_destroy` kritik resource'larda123- [ ] Secret state encryption + tfvars Git dışı124- [ ] tfsec/checkov clean (Critical=0)125- [ ] OPA/Conftest custom policy (varsa)126- [ ] Cost diff (Infracost) PR'a yapışık127- [ ] Drift detection cron aktif128- [ ] Module test (terratest / terraform test)129130## Antipattern131- **Local state**.132- **`master`/`main` ref** module source.133- **`-auto-approve`** rutin.134- **State manuel `rm`/`mv`** review'sız.135- **Cross-env tek state**.136- **`*.tfvars` secret** Git'te.137- **`count = enabled ? 1 : 0`** boolean toggle.138- **`provisioner "local-exec"`** rutin.139- **`null_resource + local-exec`** state-driven olmayan.140- **`ignore_changes = all`**.141- **`-target`** apply rutin.142- **Console click** prod'da.143- **Module versiyon `latest`** prod'da.144- **Plan output review yok**.145146## Örnek Agent Davranışı147```148User: /iac-review terraform/envs/prod/149Agent (iac-engineer):1501. Tool tespit: Terraform 1.6.4, AWS provider 5.x.1512. State: S3 backend + DynamoDB lock ✓; encryption KMS ✓; versioning ✓.1523. Module contract: 3 modül; `vpc` `master` ref kullanıyor (Critical, mutable).1534. Plan output:154 - Plan: 7 to add, 2 to change, 1 to destroy.155 - destroy: aws_db_instance.legacy → `prevent_destroy = false` (Critical).1565. Tag eksik: 4 resource'ta `CostCenter` yok (Medium).1576. Secret: `terraform.tfvars` `.gitignore`'da var ✓; `TF_VAR_DB_PASSWORD` CI ENV.1587. Security: tfsec 3 finding (1 High public S3 ACL, 2 Medium SG egress).1598. Cost: Infracost +$340/ay → RDS instance class büyütüldü.1609. Output:161 - Critical: vpc module ref pin + DB prevent_destroy + S3 ACL162 - High: SG egress163 - Medium: tag eksik 4 resource164 - 8 issue açıldı (sahip + tarih).165```166167## Çıktı Formatı168```markdown169# IaC Review: <path>170171## State / Backend172- Remote, locking, encryption, versioning, per-env173174## Module Contract175- variables / outputs / versions / source pin176177## Plan Output178```text179Plan: ... to add, ... to change, ... to destroy180```181182## Critical / High / Medium / Low183184## Security Scan185- tfsec / checkov / OPA özet186187## Cost Diff (Infracost)188- Δ $/ay189190## Action Items191| Öncelik | Aksiyon | Sahip | Bitiş | Issue |192```