
Infrastructure Code Review and Hardening
Harden infrastructure code with expert security and compliance reviews
What You Can Do
Get comprehensive security and compliance analysis of your infrastructure-as-code across Terraform, CloudFormation, Kubernetes, and other IaC formats. Claude identifies security vulnerabilities, compliance gaps, performance inefficiencies, and cost optimizations while ensuring your infrastructure follows industry best practices and regulatory requirements.
Features
Identifies misconfigurations, exposed credentials, overly permissive policies, and network exposure risks
Checks against CIS benchmarks, NIST, PCI-DSS, SOC 2, and custom regulatory requirements
Spots wasteful resource configurations, oversized instances, and unused services
Validates naming conventions, tagging strategies, resource organization, and cloud-native patterns
Suggests improvements for scalability, availability, and infrastructure resilience
Documents resource relationships and validates data flow security boundaries
Evaluates IaC readiness for cloud platform transitions or major upgrades
Creates guardrails as code (OPA, Sentinel) to prevent future misconfigurations
Example Output
Security Review Output:
- ⚠️ CRITICAL: S3 bucket policy allows public read access
Location: main.tf:45
Impact: Potential data exposure
Fix: Add BucketBlockPublicAccess or restrict Principal
- ⚠️ HIGH: RDS database not encrypted at rest
Location: prod-db.tf:12
Recommendation: Enable KmsKeyId and StorageEncrypted = true
✓ PASS: Security group implements least-privilege rules
✓ PASS: All EC2 instances have IMDSv2 enforced
Compliance Report:
CIS AWS Foundations Benchmark: 14/20 controls passing (70%)
- Missing: CloudTrail encryption, S3 versioning
- Recommend: Enable CloudWatch alarms for root account usage
SOC 2 Type II: 8/10 controls satisfied
- Network: Firewall rules properly segmented ✓
- Access Control: IAM policies need least-privilege review
What's Included
- SKILL.md: Complete infrastructure review framework
- Security checklist: OWASP, CIS, and NIST control mappings
- Compliance templates: PCI-DSS, SOC 2, and HIPAA verification checklists
- Review workflows: Terraform, CloudFormation, and Kubernetes audit procedures
- Policy-as-code examples: OPA Rego and HashiCorp Sentinel rule samples
- Cost optimization guide: Common wasteful patterns and remediation steps
Who It's For
- DevOps engineers — Validate infrastructure changes before production deployment
- Cloud architects — Design secure, compliant, multi-cloud infrastructure
- Security engineers — Audit IaC for vulnerabilities and compliance gaps
- Platform teams — Establish governance guardrails across all projects
- Compliance officers — Verify infrastructure meets regulatory requirements
Best For
- Terraform configuration security audits
- CloudFormation template compliance validation
- Kubernetes manifest and Helm chart reviews
- Multi-cloud infrastructure governance
- Pre-deployment security gate automation







