Quickstart
cli/ is a drop-in replacement for the terraform binary: every
subcommand passes straight through to real terraform unchanged, except
apply, which it intercepts to run a Policy Check first. If
the Policy Check reports a Violation, the CLI prints it and exits non-zero without ever
calling real terraform apply; otherwise it applies exactly as
terraform apply would.
clojure -Sdeps '{:deps {infratomic/cli {:local/root "../cli"}}}' -M -m infratomic.cli.main -- apply
Features
Available now
-
Policy Checks — before a real
terraform applyruns, the plan is decomposed into a speculative Datomic database and evaluated against every registered Rule. Any Violation is reported and the apply is blocked; a clean check lets it through unchanged. - Reachability (graph search) — recursive graph search over deployed infrastructure answers whether one Workload can reach another (or the public internet) across the network graph, and whether a given Principal is IAM-reachable for an action across the IAM policy graph — both as structural Datalog queries, not JSON-blob scans.
-
Scheduled Sync — in addition to the on-demand CLI
syncsubcommand, Sync now also runs automatically on a fixed interval (default 300s, configurable), so newly-appeared unmanaged resources are ingested without a manual trigger. -
Drift detection — every Terraform-managed resource's live attributes
are compared against Terraform's last-asserted values, and out-of-band child additions
and removals are flagged on parents with foreign-key-bearing children — surfaced via
GET /driftand the CLI'sdrift-checksubcommand. Detection only; nothing here mutates or reverts a Drifted resource. -
Unattended Terraform execution —
apply,import, anddestroycan run unattended, each call recorded as an Invocation, with per-resource-address locking to serialize concurrent runs against the same address. -
Auto-reconciliation — on every Sync pass, every registered policy Rule
is evaluated directly against live state, independent of Drift, and violations are
remediated automatically —
terraform applyfor a drifted managed resource, a synthesized import+destroy for an unmanaged one — with every decision recorded.
On the roadmap
- Blast-radius simulation — see what a change would actually affect before it ships.
- A safe-deploy-ordering solver — work out the order to roll changes out so nothing gets stranded mid-deploy.
- Reachability auto-fix — don't just find that something's reachable that shouldn't be; propose the fix.