Read a Terraform plan expected to be empty and report why it is not
Read a Terraform plan expected to be empty and report why it is not. Drift and planned changes are reported separately, because Terraform records them separately and they answer different questions: one is what somebody changed outside the configuration, the other is what applying would do about it. Where before and after attributes are both present, the fields that actually moved are named rather than reporting the resource as generically drifted.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/terraform-plan-drift-audit
| Category | Code and developer |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
We never call tools that send, buy, move money or file anything, not even without paying.
Example input (from the provider)
{
"body": {
"ignore_addresses": [
"aws_cloudwatch_log_group.app"
],
"plan": "{\n \"format_version\": \"1.2\",\n \"terraform_version\": \"1.9.5\",\n \"resource_changes\": [\n {\n \"address\": \"aws_db_instance.primary\",\n \"type\": \"aws_db_instance\",\n \"change\": {\n \"actions\": [\n \"delete\",\n \"create\"\n ],\n \"replace_paths\": [\n [\n \"engine_version\"\n ]\n ],\n \"before\": {\n \"engine_version\": \"14.7\",\n \"tags\": {\n \"owner\": \"platform\"\n }\n },\n \"after\": {\n \"engine_version\": \"15.4\",\n \"tags\": {\n \"owner\": \"platform\"\n }\n }\n }\n },\n {\n \"address\": \"aws_s3_bucket.exports\",\n \"type\": \"aws_s3_bucket\",\n \"change\": {\n \"actions\": [\n \"delete\"\n ],\n \"before\": {\n \"bucket\": \"exports\",\n \"tags\": {\n \"owner\": \"data\"\n }\n },\n \"after\": null\n }\n },\n {\n \"address\": \"aws_lambda_function.worker\",\n \"type\": \"aws_lambda_function\",\n \"change\": {\n \"actions\": [\n \"update\"\n ],\n \"before\": {\n \"timeout\": 30\n },\n \"after\": {\n \"timeout\": 60,\n \"runtime\": \"nodejs20.x\"\n },\n \"after_unknown\": {\n \"version\": true\n }\n }\n },\n {\n \"address\": \"aws_instance.bastion\",\n \"type\": \"aws_instance\",\n \"change\": {\n \"actions\": [\n \"create\"\n ],\n \"before\": null,\n \"after\": {\n \"instance_type\": \"m5.24xlarge\"\n }\n }\n },\n {\n \"address\": \"aws_cloudwatch_log_group.app\",\n \"type\": \"aws_cloudwatch_log_group\",\n \"change\": {\n \"actions\": [\n \"no-op\"\n ],\n \"before\": {},\n \"after\": {}\n }\n }\n ],\n \"resource_drift\": [\n {\n \"address\": \"aws_security_group.web\",\n \"type\": \"aws_security_group\",\n \"change\": {\n \"actions\": [\n \"update\"\n ],\n \"before\": {\n \"description\": \"web\",\n \"ingress_count\": 2\n },\n \"after\": {\n \"description\": \"web (edited in console)\",\n \"ingress_count\": 5\n }\n }\n }\n ]\n}"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"ignore_addresses": {
"items": {
"maxLength": 512,
"type": "string"
},
"maxItems": 500,
"minItems": 1,
"type": "array"
},
"plan": {
"maxLength": 4194304,
"type": "string"
}
},
"required": [
"plan"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}