blastcheck
blastcheck reads a terraform show -json plan and emits an Impact Manifest (the sibling impact-manifest spec repo) — a machine-readable change-safety assertion. It is the reference producer of that open format.
terraform plan -out plan.tfplan
terraform show -json plan.tfplan | blastcheck > manifest.json
terraform plan tells you what will change. blastcheck adds the layer the plan can't: for each change, is it reversible, does anything become unrecoverable, does exposure widen, and — honestly — what could it not determine.
What it does, and what it deliberately doesn't
blastcheck v0.1 is offline and plan-only. It reasons from the plan artifact alone. Wherever a verdict genuinely requires live cloud state — "is this disk attached to something serving traffic?", "does a backup exist?" — it emits unknown / not_verified with a stated reason, rather than guessing.
A direct consequence, and the point of the format: a plan-only run can never emit safe. It never verified live state, so it says caution, blocked, or unknown — never safe. Certifying safe requires the live-state enrichment that a later version (or a paid consumer) layers on. blastcheck is honest about the ceiling of what a plan alone can prove.
What it derives from the plan alone is still substantial:
- Irreversibility — e.g. a managed-disk grow is one-way (Azure can't shrink), visible in the plan diff.
- Widened exposure — an inbound NSG rule opening
0.0.0.0/0to a sensitive port; a storage account turning on public access or lowering TLS. - Data-loss risk — deleting a data-bearing resource flags the primary copy as removed and recoverability as unverified, not safe.
- Cost direction, action semantics, and a
not_verifiedstate-confidence stamp on every change.
blastcheck is a producer, not a gate. It emits the manifest and exits 0; turning that into pass/fail is a separate policy layer (a CI gate). Exit codes reflect execution, not the verdict.
Scope (v0.1, intentionally narrow)
Azure: managed disks, virtual machines, network security groups (+ rules), storage accounts, SQL databases. Anything else in the plan is recorded under extensions.skipped — never silently dropped. The narrow surface is a choice: the job of this version is to exercise the Impact Manifest schema against real plans and find its shape errors, not to be a finished product.
Install & use
pip install blastcheck
terraform show -json plan.tfplan | blastcheck # stdin
blastcheck --plan plan.json > manifest.json # from a file
blastcheck --compact # single-line JSON
No hosted service, no cloud credentials, no network, no runtime dependencies — it runs entirely against the plan file.
In CI
- run: terraform show -json tfplan > plan.json
- uses: prococonsulting/blastcheck@v0
with:
plan: plan.json
The manifest is uploaded as a build artifact and the verdict is posted on the pull request. The action does not fail the build — blastcheck is a producer, not a gate, and what a blocked verdict should do to a pipeline is a policy question that belongs to you. To gate on it:
- uses: prococonsulting/blastcheck@v0
id: bc
with:
plan: plan.json
- if: steps.bc.outputs.verdict == 'blocked'
run: exit 1
Note what you cannot write: there is no verdict == 'safe' gate to pass on a plan-only run, because a plan-only run never emits safe. A pipeline that proceeds only on a positive safety claim needs the live-state enrichment. That is the honest ceiling of what a plan by itself can prove.
Tests
The suite's primary job is to prove every emitted manifest validates against the vendored schema (blastcheck/schema/impact-manifest.schema.json) on realistic plan fixtures — that is how a schema shape error surfaces.
pip install -e ".[test]"
pytest
Relationship to the spec
blastcheck implements the Impact Manifest specification (the sibling impact-manifest repo) and vendors a pinned copy of its schema at blastcheck/schema/, which ships inside the wheel. The format is open and vendor-neutral; blastcheck is a reference implementation of it, not its owner.
Status
v0.1 — draft, narrow, and evolving alongside the spec (which does not freeze at 1.0 until this tool has run against real Terraform plans).
License
Apache-2.0. See LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file blastcheck-0.1.1.tar.gz.
File metadata
- Download URL: blastcheck-0.1.1.tar.gz
- Upload date:
- Size: 37.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
86568cb1ba83e4c4ba9ba327cd8ba6b5d2eddc645213bcb5b9b680a906876a5f
|
|
| MD5 |
6b7fbbe4d84d71b6cae6db4d10d7b42a
|
|
| BLAKE2b-256 |
b1fbf4173d812a0cf3076e030b2f89012c1b911431eb4d66897548838902dfb9
|
File details
Details for the file blastcheck-0.1.1-py3-none-any.whl.
File metadata
- Download URL: blastcheck-0.1.1-py3-none-any.whl
- Upload date:
- Size: 30.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
bec9028691da459891d76b91c937a724c992b926f599cff2fbb7cf29df7fa4d0
|
|
| MD5 |
e76d3780493c0b49ab735ff89320d1cf
|
|
| BLAKE2b-256 |
449f0500a1ca13188f2a2529ce92539d9731c26eecf1f86a6a8b5d3af185a42e
|