Skip to content

Document drawing environments you have no access to - #229

Merged
patrickchugh merged 1 commit into
mainfrom
docs/draw-any-environment
Oct 4, 2026
Merged

patrickchugh merged 1 commit into
mainfrom
docs/draw-any-environment

Conversation

@patrickchugh

Copy link
Copy Markdown
Owner

Type of Change

  • Bug Fix
  • New Feature
  • Refactor
  • Documentation

What and why

TerraVision can draw any environment from Terraform plus a variables file, including environments the reader has no access to and environments that do not exist yet. The docs never said so. This PR adds it in two places, with claims checked against the source first:

  • modules/tfwrapper.py writes terravision_override.tf containing an empty backend "local" block into the source directory, strips any Terraform Cloud cloud {} block, runs terraform init -input=false -reconfigure, selects the workspace with terraform workspace select -or-create=True <name>, and runs terraform plan -refresh=false -input=false -var-file <file> -out <plan>. The plan therefore runs against fresh empty local state and reports every resource as to be created. The override file is removed afterwards.
  • The plan does need credentials the provider accepts, because the AWS provider validates them with sts:GetCallerIdentity before planning. Tested with a local backend override: no credentials fails, fake credentials fail with InvalidClientTokenId, and credentials for an unrelated account succeed. So the docs say "no access to the target account or its state", never "no credentials". Data sources that read from the target account are called out as the exception.
  • Variables files are passed with --varfile (repeatable) and the workspace with --workspace.

Changes:

  • docs/alternatives.md, live cloud scanners: a short paragraph that scanners need access to the account they draw, while TerraVision draws from code plus a variables file, so it can draw production for engineers without production access and environments that do not exist yet. The existing sentence "needs no access to your cloud account" is tightened to "needs no access to the account it draws", since provider credentials are needed.
  • docs/faq.md: "Can I draw an environment I don't have access to?" with a direct 55-word answer and the exact --varfile command, followed by the credentials caveat, then "Can I draw dev and prod from the same code?".

Not included: a gallery pair showing the same Terraform drawn as dev and as prod. I wrote and rendered one, but TerraVision misplaces resources whose subnets come from count or for_each: an autoscaling group expands into every subnet because an id known only after apply is treated as a wildcard (_subnet_id_matches in modules/resource_handlers_aws.py), and a subnet group, load balancer or cache that references all instances of a subnet resource loses the connection as "ambiguous for_each reference" (modules/graphmaker.py). The example and renders are kept on a local branch for a follow-up once that is fixed.

Verification:

  • mkdocs build passes with no warnings.
  • Both new FAQ anchors render; no gallery anchors were added or changed.
  • No em-dashes in added lines.

Checklist

All Submissions:

  • Have you checked to ensure there aren't other open Pull Requests for the same update/change?
  • Have you written Documentation/Tests?
  • Have you done your own code-review?
  • Have you disclosed any use of AI tools and models with their version?

AI Assistance Declaration

  • Tools used: Claude Code
  • Model: Claude Fable 5.1
  • Scope: Checked the plan, backend and credential behaviour in the source and by running Terraform with a local backend override; wrote the two documentation changes; verified the build. Reviewed by the author.

Checklist for Changes to Core Features:

  • Have you discussed any major revamp with a reviewer/maintainer first? (It's okay to just raise a PR directly for minor bugfixes)
  • Have you ensured your PR is focused on one major improvement and is not trying to do too many changes at once?
  • Have you added an explanation of what your changes do and why you'd like us to include them?
  • Have you written new tests for your core changes, as applicable, and made sure the new tests PASS? (documentation only)
  • Have you successfully run all previous system wide tests with your changes locally? (mkdocs build; core code unchanged)

🤖 Generated with Claude Code

TerraVision plans Terraform against empty local state, so it draws what
the code plus a variables file would deploy, for an account the reader
cannot log in to or one that does not exist yet. The scanner comparison
and two new FAQ questions say so, with the exact --varfile command and
the real requirements: Terraform, Graphviz and credentials the provider
accepts, but no access to the target account or its state.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@patrickchugh
patrickchugh merged commit 82fb198 into main Oct 4, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant