Hold a Terraform plan to a contract the caller states
Hold a Terraform plan to a contract the caller states: resource types forbidden or permitted, tags every resource must carry, actions that must not appear, a ceiling on destructive changes, and attribute values that must not be used. Tags are read from tags, tags_all or labels, because providers differ and reading only one would report a tagged resource as untagged. Which rules ran is published, so a contract that checked nothing is visible rather than reading as a pass.
Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.
Endpoint
POST https://api.zfinia.com/x402/v1/terraform-plan-policy-audit
| Category | Code and developer |
|---|---|
| Provider host | api.zfinia.com |
| Networks | eip155:8453 |
| Payment schemes | exact |
| Self-reported calls, 30 days | 1 from 1 payers (the provider's figure, not ours) |
Our checks, last 30 days
We never call tools that send, buy, move money or file anything, not even without paying.
Example input (from the provider)
{
"body": {
"contract": {
"forbidden_actions": [
"destroy"
],
"forbidden_attribute_values": {
"instance_type": [
"m5.24xlarge",
"x1e.32xlarge"
]
},
"forbidden_types": [
"aws_iam_user"
],
"max_destructive_changes": 1,
"required_tags": [
"owner",
"cost_centre"
]
},
"plan": "{\n \"format_version\": \"1.2\",\n \"terraform_version\": \"1.9.5\",\n \"resource_changes\": [\n {\n \"address\": \"aws_db_instance.primary\",\n \"type\": \"aws_db_instance\",\n \"change\": {\n \"actions\": [\n \"delete\",\n \"create\"\n ],\n \"replace_paths\": [\n [\n \"engine_version\"\n ]\n ],\n \"before\": {\n \"engine_version\": \"14.7\",\n \"tags\": {\n \"owner\": \"platform\"\n }\n },\n \"after\": {\n \"engine_version\": \"15.4\",\n \"tags\": {\n \"owner\": \"platform\"\n }\n }\n }\n },\n {\n \"address\": \"aws_s3_bucket.exports\",\n \"type\": \"aws_s3_bucket\",\n \"change\": {\n \"actions\": [\n \"delete\"\n ],\n \"before\": {\n \"bucket\": \"exports\",\n \"tags\": {\n \"owner\": \"data\"\n }\n },\n \"after\": null\n }\n },\n {\n \"address\": \"aws_lambda_function.worker\",\n \"type\": \"aws_lambda_function\",\n \"change\": {\n \"actions\": [\n \"update\"\n ],\n \"before\": {\n \"timeout\": 30\n },\n \"after\": {\n \"timeout\": 60,\n \"runtime\": \"nodejs20.x\"\n },\n \"after_unknown\": {\n \"version\": true\n }\n }\n },\n {\n \"address\": \"aws_instance.bastion\",\n \"type\": \"aws_instance\",\n \"change\": {\n \"actions\": [\n \"create\"\n ],\n \"before\": null,\n \"after\": {\n \"instance_type\": \"m5.24xlarge\"\n }\n }\n },\n {\n \"address\": \"aws_cloudwatch_log_group.app\",\n \"type\": \"aws_cloudwatch_log_group\",\n \"change\": {\n \"actions\": [\n \"no-op\"\n ],\n \"before\": {},\n \"after\": {}\n }\n }\n ],\n \"resource_drift\": [\n {\n \"address\": \"aws_security_group.web\",\n \"type\": \"aws_security_group\",\n \"change\": {\n \"actions\": [\n \"update\"\n ],\n \"before\": {\n \"description\": \"web\",\n \"ingress_count\": 2\n },\n \"after\": {\n \"description\": \"web (edited in console)\",\n \"ingress_count\": 5\n }\n }\n }\n ]\n}"
},
"bodyType": "json",
"method": "POST",
"type": "http"
}
Promised output schema (from the provider)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"properties": {
"input": {
"additionalProperties": false,
"properties": {
"body": {
"additionalProperties": false,
"properties": {
"contract": {
"additionalProperties": false,
"properties": {
"forbidden_actions": {
"items": {
"enum": [
"create",
"update",
"destroy",
"replace"
],
"type": "string"
},
"maxItems": 8,
"minItems": 1,
"type": "array"
},
"forbidden_attribute_values": {
"type": "object"
},
"forbidden_types": {
"items": {
"maxLength": 128,
"type": "string"
},
"maxItems": 200,
"minItems": 1,
"type": "array"
},
"max_destructive_changes": {
"minimum": 0,
"type": "integer"
},
"permitted_types": {
"items": {
"maxLength": 128,
"type": "string"
},
"maxItems": 500,
"minItems": 1,
"type": "array"
},
"required_tags": {
"items": {
"maxLength": 128,
"type": "string"
},
"maxItems": 50,
"minItems": 1,
"type": "array"
}
},
"type": "object"
},
"plan": {
"maxLength": 4194304,
"type": "string"
}
},
"required": [
"plan",
"contract"
],
"type": "object"
},
"bodyType": {
"enum": [
"json",
"form-data",
"text"
],
"type": "string"
},
"method": {
"enum": [
"POST"
],
"type": "string"
},
"type": {
"const": "http",
"type": "string"
}
},
"required": [
"type",
"method",
"bodyType",
"body"
],
"type": "object"
},
"output": {
"properties": {
"example": {
"type": "object"
},
"type": {
"type": "string"
}
},
"required": [
"type"
],
"type": "object"
}
},
"required": [
"input"
],
"type": "object"
}