Skip to harness content
Open technical reference map

Production domain 06

Cloud Infrastructure & Compute

3 capabilities and 3 controls define the canonical obligation set for this domain.

Domain 06Dependencies: Security & Data Protection, Observability
Canonical pathcontrols/production-layers.v2.jsonRevision69bab1cInspect source

Applicability and claim boundary

This domain defines obligations. It does not prove that a specific repository or run satisfies them.

Applicability
Assess this domain when the authorized workload can affect its capabilities. Resolve every control as required, potentially affected, or not applicable before completion.
Proof level
The accepted formats below identify possible evidence inputs. A format alone does not establish semantic or authoritative assurance; provenance and the commissioned proof contract set the supported level.
Claim boundary
Static controls are requirements, not execution evidence, provider attestation, or proof of production readiness.

Capabilities

infrastructure-as-code

Infrastructure as Code

Keep cloud topology reproducible, reviewable, and drift-aware.

cloud-boundaries

Cloud Boundaries

Apply least privilege across IAM, network, region, and secret boundaries.

cloud-cost-governance

Cloud Cost Governance

Make ownership, budgets, forecasts, and anomaly limits explicit.

Controls

CLOUD-IAC-001Infrastructure as Code

Cloud topology is reviewable, reproducible, and drift-detected.

Accepted evidence format: Artifact, Provider report
CLOUD-BOUNDARY-001Cloud Boundaries

IAM, network, region, and secret boundaries are least-privilege.

Accepted evidence format: Artifact, Provider report
CLOUD-COST-001Cloud Cost Governance

Ownership, budgets, forecasts, and anomaly thresholds are explicit.

Accepted evidence format: Metric