Skip to content

bespoke-iac-verifiers

Retired verifier basenames are prohibited everywhere. Other executable-script basenames beginning with verify require objective source, test, script, bin, or component ownership, including at the repository root. Operational placement remains prohibited except for conventional source inside an objectively owned tool or harness.

Why

Repository-specific verifier entrypoints create parallel validation paths that drift from shared policy, owned test suites, and deployment contracts. Durable executable verification belongs in an objectively owned tool or harness.

Fix

Delete the one-off verifier and every invocation. Express the invariant in Terraform, shared policy, or a provider or runtime contract; if executable verification is durable product code, place it in conventional source inside a declared or workspace-backed tool or harness. Relocating, renaming, or translating the same check, including to TypeScript, is not remediation.

Examples

Bespoke IaC verifier

Before — rejected · error
iac/scripts/verify-dev-apply-plan.jq
After — preferred
explicit environment tfvars