File Download
There are no files associated with this item.
Links for fulltext
(May Require Subscription)
- Publisher Website: 10.1145/3694715.3695974
- Scopus: eid_2-s2.0-85215507102
Supplementary
-
Citations:
- Scopus: 0
- Appears in Collections:
Conference Paper: Unearthing Semantic Checks for Cloud Infrastructure-as-Code Programs
| Title | Unearthing Semantic Checks for Cloud Infrastructure-as-Code Programs |
|---|---|
| Authors | |
| Keywords | cloud management configuration mining infrastructure as code program analysis |
| Issue Date | 2024 |
| Citation | Sosp 2024 Proceedings of the 2024 ACM Sigops 30th Symposium on Operating Systems Principles, 2024, p. 574-589 How to Cite? |
| Abstract | Cloud infrastructures are increasingly managed by Infrastructure-as-Code (IaC) frameworks (e.g., Terraform). IaC frameworks enable cloud users to configure their resources in a declarative manner, without having to directly work with low-level cloud API calls. However, with today's IaC tooling, IaC programs that pass the compilation phase may still incur errors at deployment time, resulting in significant disruption. We observe that this stems from a fundamental semantic gap between IaC-level programs and cloud-level requirements - -even a syntactically-correct IaC program may violate cloud-level expectations. To bridge this gap, we develop Zodiac, a tool that can unearth IaC-level semantic checks on cloud-level requirements. It provides an automated pipeline to mine these checks from online IaC repositories and validate them using deployment-based testing. We have applied Zodiac to Terraform resources offered by Microsoft Azure - -a leading IaC framework and a leading cloud vendor - -where it found 500+ semantic checks where violation would produce deployment failures. With these checks, we have identified 200+ buggy Terraform projects and helped fix errors within official Azure provider usage examples. |
| Persistent Identifier | http://hdl.handle.net/10722/362950 |
| DC Field | Value | Language |
|---|---|---|
| dc.contributor.author | Qiu, Yiming | - |
| dc.contributor.author | Kon, Patrick Tser Jern | - |
| dc.contributor.author | Beckett, Ryan | - |
| dc.contributor.author | Chen, Ang | - |
| dc.date.accessioned | 2025-10-10T07:43:37Z | - |
| dc.date.available | 2025-10-10T07:43:37Z | - |
| dc.date.issued | 2024 | - |
| dc.identifier.citation | Sosp 2024 Proceedings of the 2024 ACM Sigops 30th Symposium on Operating Systems Principles, 2024, p. 574-589 | - |
| dc.identifier.uri | http://hdl.handle.net/10722/362950 | - |
| dc.description.abstract | Cloud infrastructures are increasingly managed by Infrastructure-as-Code (IaC) frameworks (e.g., Terraform). IaC frameworks enable cloud users to configure their resources in a declarative manner, without having to directly work with low-level cloud API calls. However, with today's IaC tooling, IaC programs that pass the compilation phase may still incur errors at deployment time, resulting in significant disruption. We observe that this stems from a fundamental semantic gap between IaC-level programs and cloud-level requirements - -even a syntactically-correct IaC program may violate cloud-level expectations. To bridge this gap, we develop Zodiac, a tool that can unearth IaC-level semantic checks on cloud-level requirements. It provides an automated pipeline to mine these checks from online IaC repositories and validate them using deployment-based testing. We have applied Zodiac to Terraform resources offered by Microsoft Azure - -a leading IaC framework and a leading cloud vendor - -where it found 500+ semantic checks where violation would produce deployment failures. With these checks, we have identified 200+ buggy Terraform projects and helped fix errors within official Azure provider usage examples. | - |
| dc.language | eng | - |
| dc.relation.ispartof | Sosp 2024 Proceedings of the 2024 ACM Sigops 30th Symposium on Operating Systems Principles | - |
| dc.subject | cloud management | - |
| dc.subject | configuration mining | - |
| dc.subject | infrastructure as code | - |
| dc.subject | program analysis | - |
| dc.title | Unearthing Semantic Checks for Cloud Infrastructure-as-Code Programs | - |
| dc.type | Conference_Paper | - |
| dc.description.nature | link_to_subscribed_fulltext | - |
| dc.identifier.doi | 10.1145/3694715.3695974 | - |
| dc.identifier.scopus | eid_2-s2.0-85215507102 | - |
| dc.identifier.spage | 574 | - |
| dc.identifier.epage | 589 | - |
