A Python tool for Terraform state summary
Project description
tfsumpy - Terraform Plan Summary Tool
tfsumpy is a Python-based tool that summarizes Terraform plan files to provide a clear overview of infrastructure changes. It helps DevOps teams review infrastructure changes more effectively by providing detailed plan summaries in different formats.
Features
- 🔍 Detailed plan analysis with change breakdown
- 📊 Multiple output formats (default, markdown, JSON)
- 🔒 Automatic sensitive information redaction
- 🎨 Color-coded output for better readability
- 🔄 Detailed attribute change tracking
- 📝 Template-based markdown output
- 🔧 Extensible plugin system
Installation
Install using pip:
pip install tfsumpy
Or install from source:
git clone https://github.com/rafaelherik/tfsumpy.git
cd tfsumpy
pip install .
Usage
Basic Usage
- Generate a Terraform plan JSON file:
terraform plan -out=tfplan
terraform show -json tfplan > plan.json
- Analyze the plan:
Basic summary:
tfsumpy plan.json
Show detailed changes:
tfsumpy plan.json --hide-changes=false
Show resource details:
tfsumpy plan.json --detailed
Output Formats
tfsumpy supports three output formats:
- Default (console output):
tfsumpy plan.json
- Markdown:
tfsumpy plan.json --output markdown
- JSON:
tfsumpy plan.json --output json
Example Outputs
Default Output
Terraform Plan Analysis
======================
Total Changes: 3
Create: 1
Update: 1
Delete: 1
Resource Changes:
CREATE aws_s3_bucket: data_bucket
+ bucket = "new-bucket"
UPDATE aws_instance: web_server
~ instance_type = t2.micro -> t2.small
DELETE aws_security_group: old_sg
- name = "old-sg"
Markdown Output
# Terraform Plan Analysis Report
## Summary
- **Total Resources**: 3
- **Resources to Add**: 1
- **Resources to Change**: 1
- **Resources to Destroy**: 1
## Resource Changes
### aws_s3_bucket.data_bucket
#### Changes:
- **bucket**: null → "new-bucket"
### aws_instance.web_server
#### Changes:
- **instance_type**: "t2.micro" → "t2.small"
### aws_security_group.old_sg
#### Changes:
- **name**: "old-sg" → null
---
*Generated by tfsumpy on 2024-03-14 15:30:45*
JSON Output
{
"metadata": {
"timestamp": "2024-03-14T15:30:45.123456",
"version": "1.0",
"format": "json"
},
"summary": {
"total_resources": 3,
"resources_to_add": 1,
"resources_to_change": 1,
"resources_to_destroy": 1
},
"resources": [
{
"type": "aws_s3_bucket",
"name": "data_bucket",
"action": "create",
"provider": "aws",
"module": "root",
"changes": [
{
"attribute": "bucket",
"before": null,
"after": "new-bucket"
}
]
}
]
}
Deprecated Arguments
The following arguments are deprecated and will be removed in a future version:
--changes→ Use--hide-changes=falseinstead--details→ Use--detailedinstead--markdown→ Use--output markdowninstead
Configuration
Create a custom configuration file (config.json):
{
"sensitive_patterns": [
{
"pattern": "\\b(?:password|secret|key)\\b",
"replacement": "[REDACTED]"
}
],
"risk_rules": {
"high": [
{
"pattern": "\\bdelete\\b.*\\b(database|storage)\\b",
"message": "Critical resource deletion"
}
]
}
}
Use the configuration:
tfsumpy plan.json --config config.json
Debug Mode
For troubleshooting or detailed logging:
tfsumpy plan.json --debug
This will:
- Enable verbose logging
- Show detailed error messages
- Display analysis process information
Requirements
- Python 3.10 or higher
- Terraform 1.0 or higher
Contributing
Contributions are welcome! Please feel free to submit a Pull Request. For major changes:
- Fork the repository
- Create your feature branch (
git checkout -b feature/AmazingFeature) - Commit your changes (
git commit -m 'Add some AmazingFeature') - Push to the branch (
git push origin feature/AmazingFeature) - Open a Pull Request
Please make sure to update tests as appropriate.
License
This project is licensed under the MIT License - see the LICENSE file for details.
Project Status
Status: Beta
Developer Workflow with Taskfile
This project uses Taskfile to simplify common development tasks.
Install Task
On macOS (with Homebrew):
brew install go-task/tap/go-task
On Linux:
sh -c "$(curl --location https://taskfile.dev/install.sh)" -- -d
Common Commands
- Run all tests:
task test
- Build the package:
task build - Run linting:
task lint - Install all dependencies:
task install
See all available tasks:
task --list
🧩 Extending tfsumpy (Plugins)
tfsumpy supports plug-and-play extensions! You can add your own analyzers or reporters by dropping Python files in a plugins/ directory (or specify a custom directory with --plugin-dir).
- Each plugin should define a
register(context)function that registers analyzers/reporters. - tfsumpy will automatically load and register all plugins in the directory at startup.
Example plugin:
from tfsumpy.analyzer import AnalyzerInterface, AnalyzerResult
class MyCostAnalyzer(AnalyzerInterface):
@property
def category(self): return "cost"
def analyze(self, context, **kwargs):
return AnalyzerResult(category="cost", data={"total_cost": 42})
def register(context):
context.register_analyzer(MyCostAnalyzer())
Usage:
tfsumpy plan.json --plugin-dir my_plugins/
See Extending tfsumpy for more details and advanced examples.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file tfsumpy-0.2.1.tar.gz.
File metadata
- Download URL: tfsumpy-0.2.1.tar.gz
- Upload date:
- Size: 15.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3595016260e4191e6f3b1564b592d3df336e59028bbc6e87779d357d2b022533
|
|
| MD5 |
e60b49cb5660760a83453210f2acd43a
|
|
| BLAKE2b-256 |
74774c29a91ddf99274d99790396f446c25c54a7103a0c76b0e49510ccc40ee4
|
File details
Details for the file tfsumpy-0.2.1-py3-none-any.whl.
File metadata
- Download URL: tfsumpy-0.2.1-py3-none-any.whl
- Upload date:
- Size: 17.5 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.3
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0ef89662b7aef47aaa97ff713ad87e92f98ade5cb9cc5f3aa9c9f4e6816c95c8
|
|
| MD5 |
013ad61581b686ae3dd05d0febabc2ee
|
|
| BLAKE2b-256 |
7640a8de849d09cfd9bd8141c7d1bbebc435c839b2a2fea2830e119a1e335deb
|