← all policies/FailproofAI/policies
━━ infra commands
block-kubectl
Block kubectl commands (Kubernetes cluster mutations)
━━ when it runs
PreToolUsebefore the tool call runs. a denial here means the command never executes at all.
watchesnarrowed to the Bash tool
this pack enforces: a match returns a real denial rather than being recorded and discarded. what the denial then does depends on the event above.
━━ install
this one is opt-in. taking the pack without flags leaves it off until you tick it, so install it by name if you want only this.
- just this policy
- the whole pack
- turn just this off
- pick from a list
- uninstall the pack
ships in FailproofAI/policies · v06b802b63f4f · source ↗
━━ also in infra commands
- block-terraformBlock terraform and tofu (OpenTofu) commands
- block-aws-cliBlock aws CLI commands
- block-gcloudBlock gcloud (Google Cloud) CLI commands
- block-az-cliBlock az (Azure) CLI commands
- block-helmBlock helm commands
- block-gh-pipelineBlock gh CLI pipeline-trigger subcommands (workflow run, run rerun/cancel, pr merge, release create/delete, cache delete, secret set/delete)