Document drawing environments you have no access to - #229
Merged
Merged
Conversation
TerraVision plans Terraform against empty local state, so it draws what the code plus a variables file would deploy, for an account the reader cannot log in to or one that does not exist yet. The scanner comparison and two new FAQ questions say so, with the exact --varfile command and the real requirements: Terraform, Graphviz and credentials the provider accepts, but no access to the target account or its state. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
9 of 13 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Type of Change
What and why
TerraVision can draw any environment from Terraform plus a variables file, including environments the reader has no access to and environments that do not exist yet. The docs never said so. This PR adds it in two places, with claims checked against the source first:
modules/tfwrapper.pywritesterravision_override.tfcontaining an emptybackend "local"block into the source directory, strips any Terraform Cloudcloud {}block, runsterraform init -input=false -reconfigure, selects the workspace withterraform workspace select -or-create=True <name>, and runsterraform plan -refresh=false -input=false -var-file <file> -out <plan>. The plan therefore runs against fresh empty local state and reports every resource as to be created. The override file is removed afterwards.sts:GetCallerIdentitybefore planning. Tested with a local backend override: no credentials fails, fake credentials fail withInvalidClientTokenId, and credentials for an unrelated account succeed. So the docs say "no access to the target account or its state", never "no credentials". Data sources that read from the target account are called out as the exception.--varfile(repeatable) and the workspace with--workspace.Changes:
docs/alternatives.md, live cloud scanners: a short paragraph that scanners need access to the account they draw, while TerraVision draws from code plus a variables file, so it can draw production for engineers without production access and environments that do not exist yet. The existing sentence "needs no access to your cloud account" is tightened to "needs no access to the account it draws", since provider credentials are needed.docs/faq.md: "Can I draw an environment I don't have access to?" with a direct 55-word answer and the exact--varfilecommand, followed by the credentials caveat, then "Can I draw dev and prod from the same code?".Not included: a gallery pair showing the same Terraform drawn as dev and as prod. I wrote and rendered one, but TerraVision misplaces resources whose subnets come from
countorfor_each: an autoscaling group expands into every subnet because an id known only after apply is treated as a wildcard (_subnet_id_matchesinmodules/resource_handlers_aws.py), and a subnet group, load balancer or cache that references all instances of a subnet resource loses the connection as "ambiguous for_each reference" (modules/graphmaker.py). The example and renders are kept on a local branch for a follow-up once that is fixed.Verification:
mkdocs buildpasses with no warnings.Checklist
All Submissions:
AI Assistance Declaration
Checklist for Changes to Core Features:
🤖 Generated with Claude Code