This repository was archived by the owner on Sep 28, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathsafe-infrastructure-development.mdc
More file actions
109 lines (77 loc) · 4.35 KB
/
Copy pathsafe-infrastructure-development.mdc
File metadata and controls
109 lines (77 loc) · 4.35 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
---
description: "Durable safety invariants for TradingChassis infrastructure development"
alwaysApply: true
---
# Safe Infrastructure Development
Verify first. Fix only if confirmed.
These repository guardrails are an additional protection layer. They do not replace OS sandboxing, operating-system permissions, manual confirmation, or Git review. They are not a hard sandbox or security boundary.
Implementation steps live in `implementation-workflow.mdc`. Independent review steps live in `review-workflow.mdc`.
## Language
- Respond in the language explicitly requested by the current task or prompt.
- If no response language is specified, use the language of the user's current request.
- Keep repository content in English unless the task explicitly requires otherwise.
## Verification
- Verify every reported problem against the current checkout before changing code.
- Classify findings as `confirmed`, `partially confirmed`, `not confirmed`, or `insufficient evidence`.
- Do not implement speculative fixes.
- Prefer the smallest change that addresses a confirmed problem.
## Environment safety
- Classify the execution environment before running commands:
- `reliably isolated workspace sandbox`
- `direct host`
- `remote/cloud workspace`
- `unknown`
- Do not treat an environment variable, UID, allowlist entry, or the word "sandbox" as proof of isolation.
- Unknown and direct-host environments default to static inspection only.
- Repository guardrails do not prove sandbox isolation.
## Git
- No work directly on `main`.
- No force push.
- No rebase, amend, history rewrite, automatic merge, tag mutation, or release mutation without an explicit dedicated scope.
- One logical change per branch and pull request.
- Commit, push, pull-request creation, and merge only when the current prompt explicitly authorizes that action.
- An implementation task is not permission to commit, push, or merge.
## Secrets and repository hygiene
- Do not read or output real environment files, Terraform state, tfvars, OCI credentials, private keys, kubeconfigs, Ansible Vault content, tokens, or GitHub credentials.
- Do not copy values from local environments into repository examples.
- Fake examples must be visibly non-functional (for example `example-not-a-secret`).
- Do not add real operator usernames, personal absolute home paths, copied shell prompts containing identities, live-looking OCIDs, unnecessary live environment identifiers, or likely copied public host IPs.
- Tests must describe classes of forbidden data with synthetic fixtures, not the original leaked value.
- Detector specification: `docs/REPOSITORY_SECURITY.md`. Do not duplicate it here.
## Terraform ownership
- Terraform owns OCI resources.
- Cursor must not run live `apply`, `destroy`, `import`, state manipulation, force-unlock, or credential-backed plans.
- Provider and module versions must be controlled and pinned.
- Terraform must not own normal Kubernetes application resources.
## Ansible ownership
- Ansible owns host configuration, storage, MicroK8s, and initial Argo CD bootstrap.
- Do not execute playbooks against real inventories.
- Syntax and lint evidence do not prove runtime idempotency.
- Avoid broad error suppression (`ignore_errors`, catch-all rescues without justification).
## Argo CD and Kubernetes ownership
- Argo CD owns long-lived Kubernetes resources.
- Cursor must not mutate a live cluster or read Kubernetes Secrets.
- A resource must have one clear owner.
- Out-of-band live patches require an explicit architecture decision.
## Host protection
- No package, service, firewall, routing, DNS, filesystem, mount, formatting, MicroK8s lifecycle, or host-network changes.
- Never execute the existing Version-1 bootstrap scripts automatically.
## Validation evidence
Distinguish evidence clearly:
- `live validated`
- `CI validated`
- `statically validated`
- `statically identified`
- `not yet validated`
- `intentional behavior`
- `planned`
Do not turn static validation into a live-runtime claim.
## Safety files
- Changes to `.cursor/**`, `.cursorignore`, `AGENTS.md`, safety wrappers, or their tests require a dedicated scope.
- Review the complete diff before running a newly edited safety wrapper.
- Do not weaken checks merely to make validation pass.
## Safe local validation
Use only:
- `./tools/check-agent-safety`
- `./tools/validate-safe`
after reviewing their contents when they change.