Plans, state, and source
- Remote state: state metadata and resource addresses from an S3 or Cloud Storage backend.
- HCP Terraform and Terraform Enterprise: state from the workspaces you connect.
- Pull request plans: the plan a pull request's GitHub Actions workflow publishes as an artifact.
- Deployment state: the
terraform show -jsonortofu show -jsonoutput your GitHub Actions deployment workflow publishes as an artifact. - Source: variable declarations, var-file key names, and workflow action references at the commit under review.
Before an artifact counts as evidence, Proofline matches it to its repository, workflow run, and commit. A mismatch fails the read, and the review reports the gap.
A refactor that replaces a database
In an illustrative case, a pull request moves a database into a new module. The configuration is valid, and the diff looks like a tidy refactor.
The recorded state still holds the database at its old address, and the change adds no moved block. Terraform will destroy the instance and create a new one. The RDS evidence shows that the instance serves production.
The finding cites the old address in state and the live instance. Its suggested fix is a moved block, so that Terraform keeps the existing resource.
What stays with your pipeline
Proofline reads the documents your pipeline produces and the state your backend records. It never runs Terraform against your infrastructure, and it never plans or applies.
If a configured state source cannot be read, the review is incomplete and names the missing source.
Questions
Does Proofline run terraform plan?
No. Proofline never runs Terraform against your infrastructure, and it never plans or applies. It reads recorded state and the plans your GitHub Actions workflows publish as artifacts.
Which state sources does Proofline read?
Proofline reads S3 and Cloud Storage backends, HCP Terraform and Terraform Enterprise workspaces, and the show -json output a GitHub Actions workflow publishes as an artifact.
Does Proofline work with OpenTofu?
Yes. Proofline reads OpenTofu state and output the same way it reads Terraform's.
Review Terraform changes against your state.
Review changes against AWS or review Kubernetes deployments.
Get Started with GitHub