Settings
Per-provider credentials and per-environment access. Codeface never stores long-lived keys — it assumes roles, principals and service accounts.
Cloud accounts · prod
AWS
IAM role assumption · 111122223333 · us-east-1
Azure
Scoped service principal · acme-prod-sub · eastus
GCP
Service account · acme-prod-4f2 · us-central1
Policy
- Production RDS must be encrypted and Multi-AZ.
- Object storage must block public access.
- SSH from 0.0.0.0/0 is rejected before a PR can open.
- Resource names must be lowercase DNS labels.