~ / rigs / javi-salazar / claudeops-guardrails-demo

javi-salazar/claudeops-guardrails-demo

Defense-in-depth guardrails starter for Claude Code as an SRE copilot (CLAUDE.md + settings.json + PreToolUse hook). Reference scaffold from the ClaudeOps talk.

↗ GitHub ★ 0 MIT updated 5mo ago project Claude Code
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~1.4k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit javi-salazar/claudeops-guardrails-demo/.claude ./rig-claudeops-guardrails-demo  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/gcp-logs .claude/skills/gcp-logs
$ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/incident-triage .claude/skills/incident-triage
$ npx degit javi-salazar/claudeops-guardrails-demo/.claude/skills/k8s-diagnose .claude/skills/k8s-diagnose
$ curl -fsSL --create-dirs -o .claude/agents/log-analyst.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/log-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/metrics-analyst.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/metrics-analyst.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/sre-investigator.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/sre-investigator.md
$ curl -fsSL --create-dirs -o .claude/agents/terraform-ops.md https://raw.githubusercontent.com/javi-salazar/claudeops-guardrails-demo/main/.claude/agents/terraform-ops.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(kubectl delete namespace *)",
      "Bash(kubectl delete -A *)",
      "Bash(gcloud * delete *)",
      "Bash(rm -rf *)",
      "Bash(chmod 777 *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "python3 .claude/hooks/sre-guardrail.py"
          }
        ]
      }
    ]
  }
}

Skills (3)

Subagents (5)

log-analyst
model: claude-haiku-4-5-20251001
>
metrics-analyst
model: claude-haiku-4-5-20251001
>
security-reviewer
model: claude-sonnet-4-6
>
sre-investigator
model: claude-sonnet-4-6
>
terraform-ops
model: claude-sonnet-4-6
>

Hooks (2)

eventmatcherruns
PreToolUseBashpython3 .claude/hooks/sre-guardrail.py
SessionStart*echo 'ClaudeOps started | Cluster: '$(kubectl config current-context 2>/dev/null || echo 'not configured')' | Guardrails: ACTIVE'

Permissions

deny (5)
Bash(kubectl delete namespace *)
Bash(kubectl delete -A *)
Bash(gcloud * delete *)
Bash(rm -rf *)
Bash(chmod 777 *)
ask (0)
—
allow (32)
Bash(kubectl get *)
Bash(kubectl describe *)
Bash(kubectl logs *)
Bash(kubectl top *)
Bash(kubectl config *)
Bash(kubectl rollout status *)
Bash(kubectl rollout history *)
Bash(gcloud logging read *)
Bash(gcloud monitoring time-series list *)
Bash(gcloud container clusters list *)
Bash(gcloud container clusters describe *)
Bash(gcloud container clusters get-credentials *)
Bash(gcloud compute instances list *)
Bash(gcloud config get-value *)
Bash(gcloud auth list *)
Bash(terraform init *)
Bash(terraform plan *)
Bash(terraform validate *)
Bash(terraform show *)
Bash(terraform output *)
Bash(terraform state list *)
Bash(jq *)
Bash(curl *)
Bash(cat *)
Bash(grep *)
Bash(head *)
Bash(tail *)
Bash(wc *)
Bash(date *)
Bash(echo *)
Bash(chmod +x *)
Read(*)

Similar rigs

copied ✓