DevOpsArk + Terraform
Plan scanning, drift detection and state awareness
Vendor: HashiCorp
What does the DevOpsArk Terraform integration do?
The DevOpsArk Terraform integration scans plans for insecure configuration before they are applied, detects drift between Terraform state and live infrastructure, and links running resources back to the code that created them.
What the Terraform integration provides
- Scan Terraform plans for insecure configuration before apply, as a pipeline gate.
- Detect drift between Terraform state and the live infrastructure inventory.
- Link discovered cloud resources back to the module and repository that created them.
- Identify resources in the estate that no code manages.
- Post plan findings as pull or merge request checks scoped to the change.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- Terraform plan output
- State file resource inventory where you grant access
- Module and repository structure
- Pull request checks and plan annotations
- No apply operations, Terraform execution stays in your own pipeline
Connecting Terraform
- 1Add the scan step
Call the DevOpsArk plan scan from your existing Terraform pipeline.
- 2Connect state
Grant read access to state so drift detection can compare against live inventory.
- 3Set policy
Choose which misconfiguration classes fail the plan and which warn.
Which modules use Terraform
Terraform integration: frequently asked questions
No. Terraform execution stays in your own pipeline. DevOpsArk scans the plan, reports findings and detects drift; it does not take over provisioning.
Drift is the difference between what Terraform state says exists and what actually exists, usually caused by a change made directly in a cloud console. DevOpsArk detects it by comparing state against the live inventory it already maintains.
Yes. Because the live inventory is built independently, resources present in the cloud but absent from any state file are identified, usually the resources nobody remembers creating.
As pull or merge request checks scoped to the change, so a developer sees what their plan would introduce rather than the whole backlog.
Integrations that commonly go with this one
Connect Terraform and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.