CI/CD

DevOpsArk + Terraform

Plan scanning, drift detection and state awareness

Vendor: HashiCorp

Short answer

What does the DevOpsArk Terraform integration do?

The DevOpsArk Terraform integration scans plans for insecure configuration before they are applied, detects drift between Terraform state and live infrastructure, and links running resources back to the code that created them.

Capabilities

What the Terraform integration provides

  • Scan Terraform plans for insecure configuration before apply, as a pipeline gate.
  • Detect drift between Terraform state and the live infrastructure inventory.
  • Link discovered cloud resources back to the module and repository that created them.
  • Identify resources in the estate that no code manages.
  • Post plan findings as pull or merge request checks scoped to the change.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • Terraform plan output
  • State file resource inventory where you grant access
  • Module and repository structure
Write, only if granted
  • Pull request checks and plan annotations
  • No apply operations, Terraform execution stays in your own pipeline
Setup

Connecting Terraform

  1. 1
    Add the scan step

    Call the DevOpsArk plan scan from your existing Terraform pipeline.

  2. 2
    Connect state

    Grant read access to state so drift detection can compare against live inventory.

  3. 3
    Set policy

    Choose which misconfiguration classes fail the plan and which warn.

FAQ

Terraform integration: frequently asked questions

Connect Terraform and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.