Skip to main content

blastcheck

blastcheck reads a terraform show -json plan and emits an Impact Manifest (the sibling impact-manifest spec repo) — a machine-readable change-safety assertion. It is the reference producer of that open format.

terraform plan -out plan.tfplan
terraform show -json plan.tfplan | blastcheck > manifest.json

terraform plan tells you what will change. blastcheck adds the layer the plan can't: for each change, is it reversible, does anything become unrecoverable, does exposure widen, and — honestly — what could it not determine.

What it does, and what it deliberately doesn't

blastcheck v0.1 is offline and plan-only. It reasons from the plan artifact alone. Wherever a verdict genuinely requires live cloud state — "is this disk attached to something serving traffic?", "does a backup exist?" — it emits unknown / not_verified with a stated reason, rather than guessing.

A direct consequence, and the point of the format: a plan-only run can never emit safe. It never verified live state, so it says caution, blocked, or unknown — never safe. Certifying safe requires the live-state enrichment that a later version (or a paid consumer) layers on. blastcheck is honest about the ceiling of what a plan alone can prove.

What it derives from the plan alone is still substantial:

  • Irreversibility — e.g. a managed-disk grow is one-way (Azure can't shrink), visible in the plan diff.
  • Widened exposure — an inbound NSG rule opening 0.0.0.0/0 to a sensitive port; a storage account turning on public access or lowering TLS.
  • Data-loss risk — deleting a data-bearing resource flags the primary copy as removed and recoverability as unverified, not safe.
  • Cost direction, action semantics, and a not_verified state-confidence stamp on every change.

blastcheck is a producer, not a gate. It emits the manifest and exits 0; turning that into pass/fail is a separate policy layer (a CI gate). Exit codes reflect execution, not the verdict.

Scope (v0.1, intentionally narrow)

Azure: managed disks, virtual machines, network security groups (+ rules), storage accounts, SQL databases. Anything else in the plan is recorded under extensions.skipped — never silently dropped. The narrow surface is a choice: the job of this version is to exercise the Impact Manifest schema against real plans and find its shape errors, not to be a finished product.

Install & use

pip install blastcheck
terraform show -json plan.tfplan | blastcheck            # stdin
blastcheck --plan plan.json > manifest.json              # from a file
blastcheck --compact                                     # single-line JSON

No hosted service, no cloud credentials, no network, no runtime dependencies — it runs entirely against the plan file.

In CI

- run: terraform show -json tfplan > plan.json

- uses: prococonsulting/blastcheck@v0
  with:
    plan: plan.json

The manifest is uploaded as a build artifact and the verdict is posted on the pull request. The action does not fail the build — blastcheck is a producer, not a gate, and what a blocked verdict should do to a pipeline is a policy question that belongs to you. To gate on it:

- uses: prococonsulting/blastcheck@v0
  id: bc
  with:
    plan: plan.json

- if: steps.bc.outputs.verdict == 'blocked'
  run: exit 1

Note what you cannot write: there is no verdict == 'safe' gate to pass on a plan-only run, because a plan-only run never emits safe. A pipeline that proceeds only on a positive safety claim needs the live-state enrichment. That is the honest ceiling of what a plan by itself can prove.

Tests

The suite's primary job is to prove every emitted manifest validates against the vendored schema (blastcheck/schema/impact-manifest.schema.json) on realistic plan fixtures — that is how a schema shape error surfaces.

pip install -e ".[test]"
pytest

Relationship to the spec

blastcheck implements the Impact Manifest specification (the sibling impact-manifest repo) and vendors a pinned copy of its schema at blastcheck/schema/, which ships inside the wheel. The format is open and vendor-neutral; blastcheck is a reference implementation of it, not its owner.

Status

v0.1 — draft, narrow, and evolving alongside the spec (which does not freeze at 1.0 until this tool has run against real Terraform plans).

License

Apache-2.0. See LICENSE.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

blastcheck-0.1.1.tar.gz (37.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

blastcheck-0.1.1-py3-none-any.whl (30.1 kB view details)

Uploaded Python 3

File details

Details for the file blastcheck-0.1.1.tar.gz.

File metadata

  • Download URL: blastcheck-0.1.1.tar.gz
  • Upload date:
  • Size: 37.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.2

File hashes

Hashes for blastcheck-0.1.1.tar.gz
Algorithm Hash digest
SHA256 86568cb1ba83e4c4ba9ba327cd8ba6b5d2eddc645213bcb5b9b680a906876a5f
MD5 6b7fbbe4d84d71b6cae6db4d10d7b42a
BLAKE2b-256 b1fbf4173d812a0cf3076e030b2f89012c1b911431eb4d66897548838902dfb9

See more details on using hashes here.

File details

Details for the file blastcheck-0.1.1-py3-none-any.whl.

File metadata

  • Download URL: blastcheck-0.1.1-py3-none-any.whl
  • Upload date:
  • Size: 30.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.13.2

File hashes

Hashes for blastcheck-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 bec9028691da459891d76b91c937a724c992b926f599cff2fbb7cf29df7fa4d0
MD5 e76d3780493c0b49ab735ff89320d1cf
BLAKE2b-256 449f0500a1ca13188f2a2529ce92539d9731c26eecf1f86a6a8b5d3af185a42e

See more details on using hashes here.

Release history Release notifications | RSS feed

0.3.0

2 files

0.2.0

2 files

This release

0.1.1 This release

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page