Hub rules-waypoint

rules-waypoint

v4 public Verified

Waypoint

HashiCorp Waypoint is a tool to build, deploy, and manage applications across any platform. These rules govern deployment configuration safety and application management for AI agents.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-waypoint →
Severity
4 error 3 warn 0 info
demo.cast
HashiCorp Waypoint is a tool to build, deploy, and manage applications across any platform. These rules govern deployment configuration safety and application management for AI agents.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

waypoint

waypoint-block-unsafe-patterns warning ask

RISK: NOMAD_SKIP_VERIFY=true disables TLS certificate verification for the Nomad backend — connections are vulnerable to MITM. FIX: supply the Nomad CA certificate via NOMAD_CACERT instead of disabling verification.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-env-plaintext-secret error block

RISK: Plaintext secrets in an `env` block inside waypoint.hcl are stored in the Waypoint server state database and shipped to runners in every deployment. FIX: use configdynamic() to pull secret values from Vault or AWS SSM at deploy time so they are never persisted in the Waypoint database.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-git-source-no-pin warning log

ADVISORY: A `git { url = ... }` source without a pinned `ref`, `tag`, or `commit` will always pull the latest HEAD — a supply-chain mutation in that repo deploys immediately. FIX: pin to an immutable tag or commit SHA.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-hardcoded-secret error block

RISK: Hardcoded credentials in waypoint.hcl are committed to version control and exposed to everyone with repo access (CWE-798). FIX: use Waypoint's input variables ('variable' block) with sensitive=true, or reference secrets via configdynamic() from Vault/AWS SSM/env.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-odr-privileged error block

RISK: `privileged = true` on a Waypoint on-demand runner mounts the host's Docker socket and grants full root-level access to the host — a compromised build step owns the host (CWE-269). FIX: avoid privileged mode; use rootless Docker or Kaniko for image builds.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-public-registry-no-auth warning log

ADVISORY: Pushing images to Docker Hub without authentication silently uses anonymous push, which either fails or targets a public repository. FIX: configure a registry block with credentials pulled from a secret store so images land in the correct private repository.

Rule source requires an active Pro or Enterprise subscription.
waypoint-deny-tls-skip-verify error block

RISK: Disabling TLS certificate verification in Waypoint HCL config allows MITM attacks against registry, Kubernetes, or Nomad backends (CWE-295). FIX: configure the correct CA certificate path (e.g. kubernetes { config { ... } }) instead of skipping verification.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v4
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
c8061acf54624c78b7131ae388c7a8f90373bc3c9a4d6737f7a0d133c4989270
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-waypoint/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-waypoint. The published version only bumps when a maintainer resyncs.

No commit history available.