{"slug":"api-zfinia-com-x402-v1-terraform-plan-drift-audit-120fcf","title":"Read a Terraform plan expected to be empty and report why it is not","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/terraform-plan-drift-audit","category":"code","description":"Read a Terraform plan expected to be empty and report why it is not. Drift and planned changes are reported separately, because Terraform records them separately and they answer different questions: one is what somebody changed outside the configuration, the other is what applying would do about it.","price_listed":0.16,"price_asked":null,"state":"effects","state_label":"Not tested: has real-world effects","checks_7d":0,"answered_7d":0,"latency_ms_median":null,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"ignore_addresses":["aws_cloudwatch_log_group.app"],"plan":"{\n \"format_version\": \"1.2\",\n \"terraform_version\": \"1.9.5\",\n \"resource_changes\": [\n  {\n   \"address\": \"aws_db_instance.primary\",\n   \"type\": \"aws_db_instance\",\n   \"change\": {\n    \"actions\": [\n     \"delete\",\n     \"create\"\n    ],\n    \"replace_paths\": [\n     [\n      \"engine_version\"\n     ]\n    ],\n    \"before\": {\n     \"engine_version\": \"14.7\",\n     \"tags\": {\n      \"owner\": \"platform\"\n     }\n    },\n    \"after\": {\n     \"engine_version\": \"15.4\",\n     \"tags\": {\n      \"owner\": \"platform\"\n     }\n    }\n   }\n  },\n  {\n   \"address\": \"aws_s3_bucket.exports\",\n   \"type\": \"aws_s3_bucket\",\n   \"change\": {\n    \"actions\": [\n     \"delete\"\n    ],\n    \"before\": {\n     \"bucket\": \"exports\",\n     \"tags\": {\n      \"owner\": \"data\"\n     }\n    },\n    \"after\": null\n   }\n  },\n  {\n   \"address\": \"aws_lambda_function.worker\",\n   \"type\": \"aws_lambda_function\",\n   \"change\": {\n    \"actions\": [\n     \"update\"\n    ],\n    \"before\": {\n     \"timeout\": 30\n    },\n    \"after\": {\n     \"timeout\": 60,\n     \"runtime\": \"nodejs20.x\"\n    },\n    \"after_unknown\": {\n     \"version\": true\n    }\n   }\n  },\n  {\n   \"address\": \"aws_instance.bastion\",\n   \"type\": \"aws_instance\",\n   \"change\": {\n    \"actions\": [\n     \"create\"\n    ],\n    \"before\": null,\n    \"after\": {\n     \"instance_type\": \"m5.24xlarge\"\n    }\n   }\n  },\n  {\n   \"address\": \"aws_cloudwatch_log_group.app\",\n   \"type\": \"aws_cloudwatch_log_group\",\n   \"change\": {\n    \"actions\": [\n     \"no-op\"\n    ],\n    \"before\": {},\n    \"after\": {}\n   }\n  }\n ],\n \"resource_drift\": [\n  {\n   \"address\": \"aws_security_group.web\",\n   \"type\": \"aws_security_group\",\n   \"change\": {\n    \"actions\": [\n     \"update\"\n    ],\n    \"before\": {\n     \"description\": \"web\",\n     \"ingress_count\": 2\n    },\n    \"after\": {\n     \"description\": \"web (edited in console)\",\n     \"ingress_count\": 5\n    }\n   }\n  }\n ]\n}"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"ignore_addresses":{"items":{"maxLength":512,"type":"string"},"maxItems":500,"minItems":1,"type":"array"},"plan":{"maxLength":4194304,"type":"string"}},"required":["plan"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[],"description_full":"Read a Terraform plan expected to be empty and report why it is not. Drift and planned changes are reported separately, because Terraform records them separately and they answer different questions: one is what somebody changed outside the configuration, the other is what applying would do about it. Where before and after attributes are both present, the fields that actually moved are named rather than reporting the resource as generically drifted.","last_updated":"2026-10-04T08:30:23.175Z","schemes":["exact"]}