terraform-plan-review
Created here
Use when a Terraform plan should be reviewed before it is applied, for destroyed or replaced resources, security regressions, cost and drift.
SKILL.md
Review a Terraform plan before it is applied and say what it will really do, what is risky and whether it is safe to apply. It applies nothing.
Arguments
- A plan (optional): a saved plan file, the JSON or text output of a plan, or nothing to create a plan for the current directory.
- A workspace or variable file (optional).
Flow
- Get the plan as data. With a saved plan file, run
terraform show -json <file>. With nothing given, confirm the workspace and the variable files with the user, then runterraform plan -out=<temporary file> -lock=falseandterraform show -jsonon it; delete the temporary file at the end, since a plan file can hold secrets. If credentials or the backend are unavailable, say so and review the configuration diff instead, marking every conclusion as unverified. - Sort the changes into create, update in place, replace (destroy then create, or create then destroy) and destroy, and count each. For every replace, find the attribute that forces it.
- Check what can lose data or cause downtime: destroyed or replaced databases, storage buckets, disks, queues, DNS zones and records, load balancers, key-management keys and anything with
prevent_destroyor deletion protection being removed; a replace of a resource that others depend on; a rename that shows as destroy and create where amovedblock was meant. - Check security regressions: network rules opened to the whole internet, storage made public, encryption or logging turned off, wider IAM policies (wildcard actions or resources, new admin grants), secrets shown in plain values or outputs.
- Check the rest: changes the configuration diff does not explain (drift in the real infrastructure), changes outside the intended scope, unpinned provider or module versions that moved, and resources whose size or count grew a lot (cost).
- Compare with the intent: read the configuration diff or ask what the change was meant to do, and list anything the plan does beyond it.
- Give the report. Do not apply, and do not edit the configuration unless asked.
Report
- Verdict: safe to apply, apply with care, or do not apply, in one sentence, with the workspace and the counts of creates, updates, replaces and destroys.
- Destroyed and replaced resources, each with its address, why it is replaced and what is lost.
- Risks, most severe first: the resource address, the change, the consequence and the fix.
- Unexpected changes not explained by the intent, including drift.
- What could not be checked.
SKILL.md
SKILL.md holds the skill's instructions; it is edited on the Instructions tab.
Frontmatter written into each target's SKILL.md.
Common
No fields set for this target.