Unearthing Semantic Checks for Cloud Infrastructure-as-Code Programs
Yiming Qiu, Patrick Tser Jern Kon, Ryan Beckett, Ang Chen
Abstract
Cloud infrastructures are increasingly managed by Infrastructure-as-Code (IaC) frameworks (e.g., Terraform). IaC frameworks enable cloud users to configure their resources in a declarative manner, without having to directly work with low-level cloud API calls. However, with today's IaC tooling, IaC programs that pass the compilation phase may still incur errors at deployment time, resulting in significant disruption. We observe that this stems from a fundamental semantic gap between IaC-level programs and cloud-level requirements---even a syntactically-correct IaC program may violate cloud-level expectations. To bridge this gap, we develop Zodiac, a tool that can unearth IaC-level semantic checks on cloud-level requirements. It provides an automated pipeline to mine these checks from online IaC repositories and validate them using deployment-based testing. We have applied Zodiac to Terraform resources offered by Microsoft Azure---a leading IaC framework and a leading cloud vendor---where it found 500+ semantic checks where violation would produce deployment failures. With these checks, we have identified 200+ buggy Terraform projects and helped fix errors within official Azure provider usage examples.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext eb728b07-ecf3-466c-803d-bb376bf1e8f3Cited by top-tier papers2
- Deriving Semantic Checkers from Tests to Detect Silent Failures in Production Distributed SystemsChang Lou, Dimas Shidqi Parikesit, Yujin Huang, Zhewen Yang et al.OSDI 2025 · 6 citations
- Unfulfilled Promises: LLM-Based Detection of OS Compatibility Issues in Infrastructure as CodeGeorgios-Petros Drosos, Georgios Alexopoulos, Thodoris Sotiropoulos, Dimitris Mitropoulos et al.FSE 2026
Builds on14
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- Self-Consistency Improves Chain of Thought Reasoning in Language ModelsXuezhi Wang, Jason Wei, Dale Schuurmans, Quoc V. Le et al.ICLR 2023 · 681 citations
- DistAI: Data-Driven Automated Invariant Learning for Distributed ProtocolsJianan Yao, Runzhou Tao, Ronghui Gu, Jason Nieh et al.OSDI 2021 · 76 citations
- Finding Invariants of Distributed Systems: It's a Small (Enough) World After AllTravis Hance, Marijn Heule, Ruben Martins, Bryan ParnoNSDI 2021 · 69 citations
- Rex: Preventing Bugs and Misconfiguration in Large Services Using Correlated Change AnalysisSonu Mehta, Ranjita Bhagwan, Rahul Kumar, Chetan Bansal et al.NSDI 2020 · 65 citations
Related papers
- NSync: Automated Cloud Infrastructure-as-Code Reconciliation with AI AgentsZhenning Yang, Hui Guan, Victor Nicolet, Brandon Paulsen et al.ISSTA 2026
- Metamorphic Testing for Infrastructure-as-Code EnginesDavid Spielmann, George Zakhour, Dominik Arnold, Matteo Biagiola et al.OOPSLA 2026
- Deployability-Centric Infrastructure-as-Code Generation: Fail, Learn, Refine, and Succeed through LLM-Empowered DevOps SimulationTianyi Zhang, Shidong Pan, Zejun Zhang, Zhenchang Xing et al.FSE 2026 · 1 citation
- Fidelity of Cloud Emulators: The Imitation Game of Testing Cloud-Based SoftwareAnna Mazhar, Saad Sher Alam, William X. Zheng, Yinfang Chen et al.ICSE 2025 · 2 citations
- ZEUS: Analyzing Safety of Smart ContractsSukrit Kalra, Seep Goel, Mohan Dhawan, Subodh SharmaNDSS 2018 · 595 citations
