javi-salazar/claudeops-guardrails-demo
Defense-in-depth guardrails starter for Claude Code as an SRE copilot (CLAUDE.md + settings.json + PreToolUse hook). Reference scaffold from the ClaudeOps talk.
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
Copy this rig
# review before running: this installs third-party code
$ npx degit javi-salazar/claudeops-guardrails-demo/.claude ./rig-claudeops-guardrails-demo # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/gcp-logs .claude/skills/gcp-logs $ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/incident-triage .claude/skills/incident-triage $ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/k8s-diagnose .claude/skills/k8s-diagnose
$ curl -fsSL --create-dirs -o .claude/agents/log-analyst.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/log-analyst.md $ curl -fsSL --create-dirs -o .claude/agents/metrics-analyst.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/metrics-analyst.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/sre-investigator.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/sre-investigator.md $ curl -fsSL --create-dirs -o .claude/agents/terraform-ops.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/terraform-ops.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(kubectl delete namespace *)",
"Bash(kubectl delete -A *)",
"Bash(gcloud * delete *)",
"Bash(rm -rf *)",
"Bash(chmod 777 *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "python3 .claude/hooks/sre-guardrail.py"
}
]
}
]
}
} Skills (3)
Subagents (5)
| log-analyst model: claude-haiku-4-5-20251001 | > |
| metrics-analyst model: claude-haiku-4-5-20251001 | > |
| security-reviewer model: claude-sonnet-4-6 | > |
| sre-investigator model: claude-sonnet-4-6 | > |
| terraform-ops model: claude-sonnet-4-6 | > |
Hooks (2)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | python3 .claude/hooks/sre-guardrail.py |
| SessionStart | * | echo 'ClaudeOps started | Cluster: '$(kubectl config current-context 2>/dev/null || echo 'not configured')' | Guardrails: ACTIVE' |
Permissions
deny (5)
Bash(kubectl delete namespace *)
Bash(kubectl delete -A *)
Bash(gcloud * delete *)
Bash(rm -rf *)
Bash(chmod 777 *)
ask (0)
—
allow (32)
Bash(kubectl get *)
Bash(kubectl describe *)
Bash(kubectl logs *)
Bash(kubectl top *)
Bash(kubectl config *)
Bash(kubectl rollout status *)
Bash(kubectl rollout history *)
Bash(gcloud logging read *)
Bash(gcloud monitoring time-series list *)
Bash(gcloud container clusters list *)
Bash(gcloud container clusters describe *)
Bash(gcloud container clusters get-credentials *)
Bash(gcloud compute instances list *)
Bash(gcloud config get-value *)
Bash(gcloud auth list *)
Bash(terraform init *)
Bash(terraform plan *)
Bash(terraform validate *)
Bash(terraform show *)
Bash(terraform output *)
Bash(terraform state list *)
Bash(jq *)
Bash(curl *)
Bash(cat *)
Bash(grep *)
Bash(head *)
Bash(tail *)
Bash(wc *)
Bash(date *)
Bash(echo *)
Bash(chmod +x *)
Read(*)
Similar rigs
Seme4eg/dotfiles
My $HOME
Pragmatist 681 tok ·
alipajand/agent-context-doctor
Audit agent context files like AGENTS.md, CLAUDE.md, .cursor/rules/*.mdc, .github/copilot-instructions.md, and prompt docs for quality, safety, contradictions, and repo alignment.
Fort Knox 1.5k tok ·
alipajand/agent-readiness-kit
Audit whether a software repository is ready for AI coding agents (Cursor, Codex, Claude Code, GitHub Copilot, and similar tools).
Fort Knox 1.8k tok ·
caiolombello/claude-dotfiles
—
YOLO Cowboy 1.2k tok ·