Reflex

Stop AI agents from running kubectl delete

The same kubectl delete asks in a dev context and is denied in a production one: the kube context, AWS profile, Terraform workspace, git branch and paths such as envs/prod are part of every decision. A team policy can name your production clusters, and the optional infra.kubectl_diff setting flags deletes of namespaces, PVCs, statefulsets and CRDs.

Install: npx @ursuciprian/reflex setup starts with local rules in shadow mode, no account or key. Plugins for Claude Code, Codex CLI and opencode: setup guide.

Infra guardrails: terraform, kubectl, AWS and change management

Terraform AI agent guardrails and Claude Code production safety controls, which work the same way in Codex CLI, opencode, pi and Hermes:

kubectl delete in a prod context

reflex check "kubectl --context prod-eu delete namespace payments"

The prod-destroy rule fires in both engines, with no API call:

{
 "decision": "deny",
 "rule": "destructive operation on production",
 "source": "rule",
 "policy": "rules-v12",
 "latency_s": 0,
 "answers": {}
}

kubectl --context prod-eu delete deploy/api -n web gives the same output.

kubectl delete guardrail (optional). With "infra": {"kubectl_diff": true} (off by default, because it calls the API server), kubectl apply is checked with kubectl diff and the same arguments, and kubectl delete|replace|patch with --dry-run=server -o name added at the end. Both use the current kube context (or the command's --context), the same timeout, and never a flag that writes: --dry-run=server -o name goes right after the verb, so an option of the command left waiting for a value cannot take it, and a command with its own --dry-run, --raw, --, -f - or -o is not run at all. Nor is one that names its own --kubeconfig, --server or --token, or runs with a KUBECONFIG inside its working directory: an agent's kubeconfig could carry an exec credential plugin, and an agent's server would receive your credentials. kubectl diff exits 0 for no differences, 1 for differences and above 1 on an error. Deletes of namespaces, PVCs, PVs, statefulsets or CRDs follow infra.destroy (deny by default); other deletes ask with the count; changes without deletes only add the counts. Off, or on any failure, kubectl commands are judged as before, and the production markers (--context prod, a prod kube context) still deny destructive ones.

How do I share Reflex rules with my team, like Claude Code team settings?

Commit .reflex/policy.json at the repository root (reflex policy init writes a starter). Every teammate's Reflex applies it while Claude Code, Codex CLI or another supported agent works in that repository: extra ask and deny rules, always-human patterns, production markers and a mode floor such as enforce. These team guardrails for AI coding agents can only make Reflex stricter. A team fast lane, the one part that loosens, applies only after each teammate runs reflex trust . in their own terminal, and only while the file keeps the hash they trusted. An agent shell command that edits .reflex/ or runs reflex trust gets a tamper ask, and a .reflex/ in a directory without .git is never read. Other agents' file tools are not gated, so protect .reflex/ in code review as you would CI settings.

See: GUIDE: team policy.