Gang of eight: a defect taxonomy for infrastructure as code scripts
Akond Rahman, Effat Farhana, Chris Parnin, Laurie A. Williams
Abstract
Defects in infrastructure as code (IaC) scripts can have serious consequences, for example, creating large-scale system outages. A taxonomy of IaC defects can be useful for understanding the nature of defects, and identifying activities needed to fix and prevent defects in IaC scripts. The goal of this paper is to help practitioners improve the quality of infrastructure as code (IaC) scripts by developing a defect taxonomy for IaC scripts through qualitative analysis. We develop a taxonomy of IaC defects by applying qualitative analysis on 1,448 defect-related commits collected from open source software (OSS) repositories of the Openstack organization. We conduct a survey with 66 practitioners to assess if they agree with the identified defect categories included in our taxonomy. We quantify the frequency of identified defect categories by analyzing 80,425 commits collected from 291 OSS repositories spanning across 2005 to 2019. Our defect taxonomy for IaC consists of eight categories, including a category specific to IaC called idempotency (i.e., defects that lead to incorrect system provisioning when the same IaC script is executed multiple times). We observe the surveyed 66 practitioners to agree most with idempotency. The most frequent defect category is configuration data i.e., providing erroneous configuration data in IaC scripts. Our taxonomy and the quantified frequency of the defect categories may help in advancing the science of IaC script quality.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- GLITCH: Automated Polyglot Security Smell Detection in Infrastructure as CodeNuno Saavedra, João F. FerreiraASE 2022 · 27 citations
- When Your Infrastructure Is a Buggy Program: Understanding Faults in Infrastructure as Code EcosystemsGeorgios-Petros Drosos, Thodoris Sotiropoulos, Georgios Alexopoulos, Dimitris Mitropoulos et al.OOPSLA 2024 · 14 citations
- Towards Understanding the Characteristics of Code Generation Errors Made by Large Language ModelsZhijie Wang, Zijie Zhou, Da Song, Yuheng Huang et al.ICSE 2025 · 12 citations
- State Reconciliation Defects in Infrastructure as CodeMd. Mahadi Hassan, John Salvador, Shubhra Kanti Karmaker Santu, Akond RahmanFSE 2024 · 8 citations
- Who Watches the Watchers? On the Reliability of Softwarizing Cloud Application ManagementJiawei Tyler Gu, Zhen Tang, Yiming Su, Bogdan Alexandru Stoica et al.NSDI 2026 · 3 citations
Related papers
- IoT Bugs and Development ChallengesAmir Makhshari, Ali MesbahICSE 2021 · 76 citations
- Leveraging Practitioners' Feedback to Improve a Security LinterSofia Reis, Rui Abreu, Marcelo d'Amorim, Daniel FortunatoASE 2022 · 16 citations
- We'll Fix It in Post: What Do Bug Fixes in Video Game Update Notes Tell Us?Andrew Truelove, Eduardo Santana de Almeida, Iftekhar AhmedICSE 2021 · 19 citations
- Preempting Flaky Tests via Non-Idempotent-Outcome TestsAnjiang Wei, Pu Yi, Zhengxi Li, Tao Xie et al.ICSE 2022 · 20 citations
- What Makes a Good Commit Message?Yingchen Tian, Yuxia Zhang, Klaas-Jan Stol, Lin Jiang et al.ICSE 2022 · 90 citations
