{"slug":"api-zfinia-com-x402-v1-terraform-plan-policy-audit-319f26","title":"Hold a Terraform plan to a contract the caller states","host":"api.zfinia.com","method":"POST","resource":"https://api.zfinia.com/x402/v1/terraform-plan-policy-audit","category":"code","description":"Hold a Terraform plan to a contract the caller states: resource types forbidden or permitted, tags every resource must carry, actions that must not appear, a ceiling on destructive changes, and attribute values that must not be used. Tags are read from tags, tags_all or labels, because providers dif","price_listed":0.2,"price_asked":null,"state":"effects","state_label":"Not tested: has real-world effects","checks_7d":0,"answered_7d":0,"latency_ms_median":null,"reported_calls_30d":1,"reported_payers_30d":1,"networks":["eip155:8453"],"badge":"unverified","paid_checks_7d":0,"paid_ok_7d":0,"example_input":{"body":{"contract":{"forbidden_actions":["destroy"],"forbidden_attribute_values":{"instance_type":["m5.24xlarge","x1e.32xlarge"]},"forbidden_types":["aws_iam_user"],"max_destructive_changes":1,"required_tags":["owner","cost_centre"]},"plan":"{\n \"format_version\": \"1.2\",\n \"terraform_version\": \"1.9.5\",\n \"resource_changes\": [\n  {\n   \"address\": \"aws_db_instance.primary\",\n   \"type\": \"aws_db_instance\",\n   \"change\": {\n    \"actions\": [\n     \"delete\",\n     \"create\"\n    ],\n    \"replace_paths\": [\n     [\n      \"engine_version\"\n     ]\n    ],\n    \"before\": {\n     \"engine_version\": \"14.7\",\n     \"tags\": {\n      \"owner\": \"platform\"\n     }\n    },\n    \"after\": {\n     \"engine_version\": \"15.4\",\n     \"tags\": {\n      \"owner\": \"platform\"\n     }\n    }\n   }\n  },\n  {\n   \"address\": \"aws_s3_bucket.exports\",\n   \"type\": \"aws_s3_bucket\",\n   \"change\": {\n    \"actions\": [\n     \"delete\"\n    ],\n    \"before\": {\n     \"bucket\": \"exports\",\n     \"tags\": {\n      \"owner\": \"data\"\n     }\n    },\n    \"after\": null\n   }\n  },\n  {\n   \"address\": \"aws_lambda_function.worker\",\n   \"type\": \"aws_lambda_function\",\n   \"change\": {\n    \"actions\": [\n     \"update\"\n    ],\n    \"before\": {\n     \"timeout\": 30\n    },\n    \"after\": {\n     \"timeout\": 60,\n     \"runtime\": \"nodejs20.x\"\n    },\n    \"after_unknown\": {\n     \"version\": true\n    }\n   }\n  },\n  {\n   \"address\": \"aws_instance.bastion\",\n   \"type\": \"aws_instance\",\n   \"change\": {\n    \"actions\": [\n     \"create\"\n    ],\n    \"before\": null,\n    \"after\": {\n     \"instance_type\": \"m5.24xlarge\"\n    }\n   }\n  },\n  {\n   \"address\": \"aws_cloudwatch_log_group.app\",\n   \"type\": \"aws_cloudwatch_log_group\",\n   \"change\": {\n    \"actions\": [\n     \"no-op\"\n    ],\n    \"before\": {},\n    \"after\": {}\n   }\n  }\n ],\n \"resource_drift\": [\n  {\n   \"address\": \"aws_security_group.web\",\n   \"type\": \"aws_security_group\",\n   \"change\": {\n    \"actions\": [\n     \"update\"\n    ],\n    \"before\": {\n     \"description\": \"web\",\n     \"ingress_count\": 2\n    },\n    \"after\": {\n     \"description\": \"web (edited in console)\",\n     \"ingress_count\": 5\n    }\n   }\n  }\n ]\n}"},"bodyType":"json","method":"POST","type":"http"},"output_schema":{"$schema":"https://json-schema.org/draft/2020-12/schema","properties":{"input":{"additionalProperties":false,"properties":{"body":{"additionalProperties":false,"properties":{"contract":{"additionalProperties":false,"properties":{"forbidden_actions":{"items":{"enum":["create","update","destroy","replace"],"type":"string"},"maxItems":8,"minItems":1,"type":"array"},"forbidden_attribute_values":{"type":"object"},"forbidden_types":{"items":{"maxLength":128,"type":"string"},"maxItems":200,"minItems":1,"type":"array"},"max_destructive_changes":{"minimum":0,"type":"integer"},"permitted_types":{"items":{"maxLength":128,"type":"string"},"maxItems":500,"minItems":1,"type":"array"},"required_tags":{"items":{"maxLength":128,"type":"string"},"maxItems":50,"minItems":1,"type":"array"}},"type":"object"},"plan":{"maxLength":4194304,"type":"string"}},"required":["plan","contract"],"type":"object"},"bodyType":{"enum":["json","form-data","text"],"type":"string"},"method":{"enum":["POST"],"type":"string"},"type":{"const":"http","type":"string"}},"required":["type","method","bodyType","body"],"type":"object"},"output":{"properties":{"example":{"type":"object"},"type":{"type":"string"}},"required":["type"],"type":"object"}},"required":["input"],"type":"object"},"history":[],"description_full":"Hold a Terraform plan to a contract the caller states: resource types forbidden or permitted, tags every resource must carry, actions that must not appear, a ceiling on destructive changes, and attribute values that must not be used. Tags are read from tags, tags_all or labels, because providers differ and reading only one would report a tagged resource as untagged. Which rules ran is published, so a contract that checked nothing is visible rather than reading as a pass.","last_updated":"2026-10-04T08:29:12.793Z","schemes":["exact"]}