Upcoming Workshop: Citizen Developer Agentic Software Factory on AWS
Register Here!Claude built the app. Now it needs a database.
You are halfway through a session. The service runs locally, the tests pass, and you ask Claude Code to add Postgres and put the thing somewhere your team can reach it. Claude is willing. It will run the AWS CLI with whatever profile is loaded, write Terraform from scratch, or both.
That works on a personal project. On a company cloud account it means Claude acts with your role’s full reach, picks resource types and settings on its own, and leaves infrastructure behind that nobody on the platform team designed or knows about. The key it used is in the session’s environment the whole time.
Ways to give Claude Code infrastructure access
Each of these is in use today. They differ in what Claude is allowed to decide and what your team inherits afterward.
The cloud CLI with your profile
Immediate results. No setup, no waiting.
Claude has your role’s reach and chooses the resources. The credentials sit in the session, and nothing records the change as Claude’s.
Claude writes Terraform and applies it
Reproducible infrastructure in code.
Claude invents a new set of definitions for each app, and your team maintains them from then on.
Claude opens Terraform pull requests
A review before anything is applied.
Review becomes the limit. Someone reads every generated module, at the speed Claude writes them.
An MCP server over raw cloud APIs
A cleaner interface for Claude than shell commands.
The tools still expose whatever the underlying credential allows, so the reach is the same.
Massdriver MCP server and the Architect plugin
Claude plans from the bundles your platform team published, holds a scoped Massdriver token, and its changes go through policy and approvals.
Your platform team publishes the bundles first, from the Terraform, OpenTofu, and Helm it already runs.
Give Claude Code a catalog instead of a cloud account
Massdriver Architect is a Claude Code plugin. When you describe what the app needs, Architect reads the catalog your platform team published and composes the app from those bundles only. If the catalog cannot meet a requirement, Architect says so and drafts a request to the platform team, and it does not improvise a workaround. Two commands install it, and the get-started guide has them.
Claude never receives a cloud key. It holds a Massdriver token scoped to a service account, and that account’s group decides which actions it may take in which environments. Massdriver holds the cloud credentials and uses them only for deploys that policy allows.
One request, from prompt to deploy
You ask Claude Code for a queue and somewhere to store generated reports.
- 01What happens
Architect reads the catalog and the project’s existing infrastructure through the Massdriver MCP server.
What the record showsA read. Claude sees the approved queue and storage bundles for your team, and what is already running.
- 02What happens
Architect plans the app from approved bundles. The project already has a Postgres database, so the app gets a schema in it instead of a second database.
What the record showsThe plan names each bundle and version it uses.
- 03What happens
The parameters Claude sets are checked against each bundle’s schema, and policy checks run on the plan.
What the record showsValues outside what your platform team allowed are rejected. Policy results are attached to the change.
- 04What happens
Your grant allows deploys to dev, so the queue and storage come up there.
What the record showsThe deploy is recorded with the service account as the actor.
- 05What happens
Claude proposes the production change. A teammate with deploy permission approves it.
What the record showsThe approver is named on the change.
What Claude can see before it asks for anything
Through the Context Engine, Claude can query what is deployed, how it connects, who owns it, and what it may change. One query replaces the dozens of cloud API calls and repository searches Claude would otherwise make, and the answer reflects what is actually deployed.
That context is also what keeps the plans small. When Claude knows which instance classes and engine versions the bundle allows, it does not propose one your platform team never published.
When Claude asks for something the catalog does not have
Sooner or later the app needs a capability your platform team has not published, such as an email service or a search cluster. Without a catalog, Claude fills the gap itself, with a new resource type, a new module, or a call to a third-party API under somebody’s personal account.
Architect stops at the edge of the catalog. It tells you which requirement it cannot meet, drafts a catalog request to the platform team, and builds the rest of the app from what is approved. The platform team sees the demand, and decides whether to publish a bundle for it.
Production stays a human decision
Proposing a change and deploying it are separate permissions in Massdriver. Most teams let Claude Code deploy to dev and preview environments and propose changes to production, where a person reviews the diff and the policy results before anything runs. You can widen that later, environment by environment.
Revoking the token, or removing the service account from its group, ends Claude’s access with no change to your cloud IAM.
Questions developers and platform teams ask
Does Claude Code need AWS, Azure, or GCP credentials?
No. Claude holds a scoped Massdriver token. Massdriver keeps the cloud credentials and uses them only for deploys that policy allows.
Does Claude write our Terraform?
It does not have to. Your existing Terraform, OpenTofu, and Helm modules, published as bundles, define what Claude can deploy. Claude sets their parameters.
Can Claude see what is already running?
Yes, through the Context Engine: deployed components, their connections, owners, and deployment history, scoped to what its service account may read.
Can Claude make a production change?
Only if you grant it. A common setup lets Claude propose production changes and leaves the deploy to a person.
Does this only work with Claude Code?
No. The MCP server is the integration point, and any agent that speaks MCP can use the same catalog, policies, and approvals. The Architect plugin is the Claude Code front end.
What happens to the infrastructure if we stop using Claude Code?
It keeps running. It is built from your bundles in your cloud, and your team manages it in Massdriver like any other deployment.
Watch Architect in Claude Code
A two-minute demo: a developer describes an app in Claude Code, and Architect builds it only from the approved catalog, under the same policy as every other change.
One governed path, for agents and every other change.
Give us an hour with your platform and security leads, and within a day you have a governed path running on your own infrastructure, ready to prove for 30 days.