Holds agent-authored database migrations and `terraform apply` runs until a human signs the blast radius.
For: Backend and platform teams whose agents can reach migrations and IaC
Escalates any migration that drops a column or table; allows additive ones.
Escalates infrastructure changes that touch IAM, security groups, or networking.
Blocks a resource delete or force-replace unless an explicit approval label is present.
# Claude Code Migration & Infra Gate
# Fork: mirrors the DECIONIS_POLICY.md rules shipped with the GitHub examples.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: claude-code-migration-and-infra-gate
surface: claude_code
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
rules:
- name: destructive_migration_escalation
when: "change.kind == 'migration'"
decision: |
ESCALATE IF migration.drops_column == true OR migration.drops_table == true
ALLOW OTHERWISE
reason_code: destructive_migration_requires_approval
- name: iam_and_network_change
when: "tool == 'Bash' AND command matches '(terraform apply|pulumi up|cdk deploy)'"
decision: |
ESCALATE IF context.touches_iam == true OR context.touches_network == true
ALLOW OTHERWISE
reason_code: privileged_infra_change
- name: force_replace_block
when: "tool == 'Bash' AND command matches '(terraform|pulumi)'"
decision: |
BLOCK IF plan.destroys_resources == true AND pr.labels not contains 'approved-destructive'
ALLOW OTHERWISE
reason_code: unlabeled_destructive_plan
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.