How close AWS is

This page is for people building choudoufu. If you are deciding whether to use it, the claims are the proof surface: each promise is a scenario you can run, with an arm that breaks it on purpose. That ruling is #643’s, building on #522’s split of the old single headline number.

What this page measures is breadth and regression. An estate is a real OpenTofu or Terraform configuration someone else wrote, pinned by commit, run through every stage below side by side with stock OpenTofu. It is clear when every headline stage passes. Real, externally authored configurations surface defects no purpose-built scenario anticipates, so the board is the net that catches them. It is re-measured on a cadence, when the maintainer dispatches the Gauntlet workflow (typically before a release), not on every change, so a row is as current as its commit and date.

Core estates
26 of 26 estates behave like OpenTofu
0 verified on the current pins, 26 carried from a run on an earlier pin
  • Cold deploy: 25 pass, 0 fail, 0 not run
  • Migrate: 25 pass, 0 fail, 0 not run
  • Replan from nothing: 25 pass, 0 fail, 0 not run
  • No-op apply: 25 pass, 0 fail, 0 not run
  • Drift and reconverge: 25 pass, 0 fail, 0 not run
  • Rename: 25 pass, 0 fail, 0 not run
  • Remove a block: 25 pass, 0 fail, 0 not run
  • Change count: 25 pass, 0 fail, 0 not run
  • Replace with create_before_destroy: 25 pass, 0 fail, 0 not run
  • Crash mid-apply: 1 pass, 0 fail, 24 not run
  • Teardown: 0 pass, 0 fail, 25 not run
  • Plan, review, apply: 25 pass, 0 fail, 0 not run
  • Greenfield apply: 25 pass, 0 fail, 0 not run
  • Strict profile: 1 pass, 0 fail, 24 not run
  • Plan with no local state: 0 pass, 0 fail, 25 not run
All estates
27 of 28 estates behave like OpenTofu
0 verified on the current pins, 27 carried from a run on an earlier pin
  • Cold deploy: 26 pass, 0 fail, 0 not run
  • Migrate: 26 pass, 0 fail, 0 not run
  • Replan from nothing: 26 pass, 0 fail, 0 not run
  • No-op apply: 26 pass, 0 fail, 0 not run
  • Drift and reconverge: 26 pass, 0 fail, 0 not run
  • Rename: 26 pass, 0 fail, 0 not run
  • Remove a block: 26 pass, 0 fail, 0 not run
  • Change count: 26 pass, 0 fail, 0 not run
  • Replace with create_before_destroy: 26 pass, 0 fail, 0 not run
  • Crash mid-apply: 1 pass, 0 fail, 25 not run
  • Teardown: 0 pass, 0 fail, 26 not run
  • Plan, review, apply: 26 pass, 0 fail, 0 not run
  • Greenfield apply: 26 pass, 0 fail, 0 not run
  • Strict profile: 1 pass, 0 fail, 25 not run
  • Plan with no local state: 0 pass, 0 fail, 26 not run
kubernetes lane
11 of 11 estates behave like OpenTofu
0 verified on the current pins, 11 carried from a run on an earlier pin
  • Cold deploy: 11 pass, 0 fail, 0 not run
  • Migrate: 11 pass, 0 fail, 0 not run
  • Replan from nothing: 11 pass, 0 fail, 0 not run
  • No-op apply: 11 pass, 0 fail, 0 not run
  • Drift and reconverge: 11 pass, 0 fail, 0 not run
  • Rename: 11 pass, 0 fail, 0 not run
  • Remove a block: 11 pass, 0 fail, 0 not run
  • Change count: 11 pass, 0 fail, 0 not run
  • Replace with create_before_destroy: 11 pass, 0 fail, 0 not run
  • Crash mid-apply: 11 pass, 0 fail, 0 not run
  • Teardown: 11 pass, 0 fail, 0 not run
  • Plan, review, apply: 11 pass, 0 fail, 0 not run
  • Greenfield apply: 11 pass, 0 fail, 0 not run
  • Strict profile: 11 pass, 0 fail, 0 not run
  • Plan with no local state: 2 pass, 0 fail, 9 not run

Behaviors proven: 1 of 15 stages have their representative-set fixtures passing against the tier-1 behavior matrix - a development-loop signal for contributors, not a coverage claim; it neither substitutes for the bars above nor gates anything on this page.

Estates above were last measured against different emulator pins: 27 against ghcr.io/lex00/floci@sha256:6c3d5c2dac72209e6f2e45c08902e783480d4d34f48d25daba8da94b9f882072, 11 against an unrecorded image. The current pin is ghcr.io/lex00/floci@sha256:ff46eb8d1b73a9727948d1a194a660972e44cc64164a486548da7cb468a09144; a row not measured against it is stale evidence, not a failure.

The engine is built on OpenTofu 1.13.0 (version/VERSION). Of the 38 estates measured so far, 38 recorded running on it.

The two AWS bars count every estate that runs on the emulator. The third is the kubernetes lane, whose estates run against a real API server on a kind cluster and count toward neither AWS bar.

Every estate below last ran against emulator image ghcr.io/lex00/floci@sha256:6c3d5c2dac72209e6f2e45c08902e783480d4d34f48d25daba8da94b9f882072, recorded between 2026-10-02T19:19:40Z and 2026-10-05T03:17:01Z. Each row below carries its own last_run date; they are not all the same run. The pin has since moved to ghcr.io/lex00/floci@sha256:ff46eb8d1b73a9727948d1a194a660972e44cc64164a486548da7cb468a09144; every row below is stale evidence against the current image. 27 of 39 rows below were measured before their own estate directory, or the shared protocol library they source, last changed. Their verdicts describe an earlier version of the crossing script: a stage one of those edits broke still reads pass here until the estate is re-run, and a stage one of them fixed still reads fail (#1264). The rows are corpus-alb-complete, corpus-autoscaling-complete, corpus-dynamodb-table-basic, corpus-ec2-instance-complete, corpus-ecs-fargate, corpus-eks-basic, corpus-evoteum-modules, corpus-giantswarm-crossplane, corpus-hongbomiao-harbor, corpus-hongbomiao-labelbox, corpus-hongbomiao-storage, corpus-iam-policy, corpus-iam-read-only-policy, corpus-lambda-simple, corpus-leynos-monitoring, corpus-mastino-dns, corpus-overture-tiles, corpus-rds-complete-postgres, corpus-s3-bucket-complete, corpus-security-group-complete, corpus-simpleinfra-dns, corpus-sqs-basic, corpus-sumaform-aws, corpus-vpc-complete, corpus-xancloud-iac, reference-ec2-vpc, terralith-scale. 1 more cannot be checked from this checkout: reference-eks.

A row describes its crossing script as it stood the day it ran; the line above counts rows whose script has changed since, without failing the build (live/GAUNTLET.md has why).

The behaviors-proven line counts how many of the 15 stages have a fast fixture that runs in minutes. A stage without one is still proven by the estates, only slowly.

Every table on this page is rendered from site/data/gauntlet_board.json and site/data/gauntlet.json, both written by go run ./tools/gauntlet render; the prose around them is the only thing typed by hand.

The stages

StageStatusHeadlineWhat a pass proves
1Cold deployactiveyesThe estate is real and buildable: the stock binary applies the unmodified configuration against the emulator, with no live block and no choudoufu involved.
2Migrateactiveyeschoudoufu live-import -approve against the stock state file binds every instance: each state entry becomes a marker on the resource, a record, or an identity derived from the declaration, and the summary line reports zero skipped.
3Replan from nothingactiveyesWith the state file deleted, choudoufu live-plan is empty, and a representative set of rendered identities equals what the AWS CLI reports for the same objects.
4No-op applyactiveyesApplying the empty plan changes nothing: the estate’s tagged-object count before and after is identical.
5Drift and reconvergeactiveyesOne live object is mutated out of band through the AWS CLI; the next plan proposes fixing exactly that object and nothing else, and apply reconverges it.
6RenameactiveyesRenaming a resource through a moved block and through choudoufu live-mv both produce zero churn: no destroy, no create, the marker rewritten in place.
7Remove a blockactiveyesDeleting a resource block destroys the object under the default policy, in an order the cloud accepts, including blocks for untaggable children whose parents stay.
8Change countactiveyesScaling a count block down and back up destroys and creates only the instances stock would, and every surviving instance keeps its identity.
9Replace with create_before_destroyactiveyesA forced replacement under create_before_destroy creates the new object, destroys the old one, and the next plan is empty with no marker collision.
10Crash mid-applyactiveyes (tier-1 gated)A replace interrupted after the create and before the destroy is recovered by the next plan without a human: the old object is destroyed, the new one is bound.
11Teardownactiveyes (tier-1 gated)choudoufu apply -destroy removes every object the estate owns in one apply, in an order the cloud accepts, and leaves nothing marked.
12Plan, review, applyactiveyesplan -out followed by apply <planfile> applies when the world has not moved and refuses, naming the mismatch, when it has.
13Greenfield applyactiveyesApplying the same configuration from an empty account with choudoufu directly, no migration, produces the same objects stock’s cold deploy produced, plus markers.
14Strict profileactivenoWith every strict toggle on, the estate is refused for exactly the things the toggles name (secrets stored, markers unrepaired, and so on) with the documented message, and for nothing else.
15Plan with no local stateactivenoAfter the estate is applied and its plan is empty, deleting BOTH the local record store and the state cache - a fresh clone or a new machine, with only the account left - still yields a plan that finds every declared object by its own marker or a stamped parent: nothing created, destroyed or replaced.

Planned stages show the target and count toward nothing until activated. live/GAUNTLET.md defines every stage, what stock answers, how each check is proven non-vacuous, and what activating one does to the bars.

The estates

EstateSetLaneClearStages
corpus-alb-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-autoscaling-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-dynamodb-table-basiccoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-ec2-instance-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-ecs-fargatecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-eks-basiccoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-evoteum-modulescoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-giantswarm-crossplanecoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-hongbomiao-harborcoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-hongbomiao-labelboxcoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-hongbomiao-storagecoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-iam-policycoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-iam-read-only-policycoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-lambda-simplecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-leynos-monitoringcoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-overture-tilescoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-rds-complete-postgrescoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-s3-bucket-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-security-group-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-simpleinfra-dnscoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-sqs-basiccoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-sumaform-awscoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-vpc-completecoreterraform-popularyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-xancloud-iaccoreopentofu-nativeyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
reference-ec2-vpccorereferenceyes script changedpass pass pass pass pass pass pass pass pass pass not run pass pass pass not run
terralith-scalecorereferenceyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-cloud-platform-componentsgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
corpus-govuk-cluster-accessgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
corpus-govuk-cluster-servicesgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
corpus-k8s-metrics-servergrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
corpus-mastino-dnsgrowingpublished-deploymentyes script changedpass pass pass pass pass pass pass pass pass not run not run pass pass not run not run
corpus-quickpizzagrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
reference-eksgrowingreferenceno script unknownnot run not run not run not run not run not run not run not run not run not run not run not run not run not run not run
reference-k8sgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
reference-k8s-cert-managergrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
reference-k8s-platform-appgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass pass
reference-k8s-shared-objectsgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass pass
reference-k8s-statefulgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run
reference-k8s-workloadsgrowingkubernetesyespass pass pass pass pass pass pass pass pass pass pass pass pass pass not run

Run time

38 of 39 estates have a recorded run duration, totaling 6h41m40.9s, but not from one sweep: 2h58m52s across 11 estate(s) at commit 4bfb459f95; 12m18.9s across 2 estate(s) at commit 66a25ed700; 16m58.5s across 2 estate(s) at commit debf8ccd05; 3h13m31.5s across 23 estate(s) at commit f707182267. This total spans different commits, not a single board run, and excludes 1 estate(s) with no recorded duration yet.
EstateTotalPer-stage (active stages, seconds recorded this run)
corpus-alb-complete10m55.1scold_deploy 1m49s, migrate 1m21s, test_plan 9s, test_apply 11s, drift_reconverge 51s, day2_rename 38s, day2_remove 38s, day2_count 1m47s, day2_replace 49s, plan_approval 51s, greenfield 1m51s
corpus-autoscaling-complete10m18.4scold_deploy 1m52s, migrate 1m16s, test_plan 10s, test_apply 11s, drift_reconverge 21s, day2_rename 39s, day2_remove 33s, day2_count 1m58s, day2_replace 35s, plan_approval 51s, greenfield 1m50s
corpus-dynamodb-table-basic4m54.6scold_deploy 31s, migrate 1m9s, test_plan 5s, test_apply 6s, drift_reconverge 11s, day2_rename 21s, day2_remove 13s, day2_count 52s, day2_replace 21s, plan_approval 27s, greenfield 38s
corpus-ec2-instance-complete9m43.2scold_deploy 1m15s, migrate 39s, test_plan 12s, test_apply 11s, drift_reconverge 15s, day2_rename 29s, day2_remove 39s, day2_count 3m13s, day2_replace 1m2s, plan_approval 39s, greenfield 1m9s
corpus-ecs-fargate12m59scold_deploy 1m37s, migrate 1m10s, test_plan 58s, test_apply 14s, drift_reconverge 25s, day2_rename 1m16s, day2_remove 34s, day2_count 2m2s, day2_replace 36s, plan_approval 1m7s, greenfield 3m0s
corpus-eks-basic9m41.4scold_deploy 1m36s, migrate 39s, test_plan 9s, test_apply 13s, drift_reconverge 24s, day2_rename 40s, day2_remove 33s, day2_count 1m58s, day2_replace 33s, plan_approval 58s, greenfield 1m55s
corpus-evoteum-modules3m2.1scold_deploy 33s, migrate 24s, test_plan 5s, test_apply 3s, drift_reconverge 8s, day2_rename 14s, day2_remove 10s, day2_count 19s, day2_replace 16s, plan_approval 17s, greenfield 33s
corpus-giantswarm-crossplane3m38.6scold_deploy 35s, migrate 16s, test_plan 5s, test_apply 12s, drift_reconverge 7s, day2_rename 16s, day2_remove 9s, day2_count 1m9s, day2_replace 10s, plan_approval 19s, greenfield 21s
corpus-hongbomiao-harbor6m15.9scold_deploy 23s, migrate 25s, test_plan 7s, test_apply 15s, drift_reconverge 11s, day2_rename 19s, day2_remove 16s, day2_count 1m37s, day2_replace 16s, plan_approval 28s, greenfield 1m58s
corpus-hongbomiao-labelbox6m3scold_deploy 12s, migrate 56s, test_plan 10s, test_apply 18s, drift_reconverge 14s, day2_rename 22s, day2_remove 32s, day2_count 1m21s, day2_replace 17s, plan_approval 30s, greenfield 1m11s
corpus-hongbomiao-storage4m27.9scold_deploy 35s, migrate 43s, test_plan 5s, test_apply 5s, drift_reconverge 10s, day2_rename 21s, day2_remove 11s, day2_count 37s, day2_replace 17s, plan_approval 23s, greenfield 1m0s
corpus-iam-policy3m59.9scold_deploy 25s, migrate 13s, test_plan 6s, test_apply 13s, drift_reconverge 10s, day2_rename 17s, day2_remove 13s, day2_count 1m0s, day2_replace 14s, plan_approval 24s, greenfield 44s
corpus-iam-read-only-policy6m41.6scold_deploy 19s, migrate 1m8s, test_plan 6s, test_apply 19s, drift_reconverge 21s, day2_rename 25s, day2_remove 33s, day2_count 1m33s, day2_replace 25s, plan_approval 54s, greenfield 38s
corpus-lambda-simple4m30.5scold_deploy 34s, migrate 20s, test_plan 4s, test_apply 9s, drift_reconverge 24s, day2_rename 35s, day2_remove 16s, day2_count 48s, day2_replace 23s, plan_approval 24s, greenfield 33s
corpus-leynos-monitoring2m35.4scold_deploy 34s, migrate 26s, test_plan 4s, test_apply 3s, drift_reconverge 7s, day2_rename 8s, day2_remove 8s, day2_count 23s, day2_replace 8s, plan_approval 15s, greenfield 18s
corpus-overture-tiles9m4scold_deploy 1m12s, migrate 59s, test_plan 18s, test_apply 17s, drift_reconverge 14s, day2_rename 1m24s, day2_remove 57s, day2_count 1m8s, day2_replace 12s, plan_approval 22s, greenfield 2m1s
corpus-rds-complete-postgres14m20.1scold_deploy 1m49s, migrate 30s, test_plan 21s, test_apply 10s, drift_reconverge 18s, day2_rename 34s, day2_remove 1m42s, day2_count 1m41s, day2_replace 3m5s, plan_approval 46s, greenfield 3m23s
corpus-s3-bucket-complete9m27.2scold_deploy 1m38s, migrate 1m6s, test_plan 6s, test_apply 13s, drift_reconverge 25s, day2_rename 29s, day2_remove 26s, day2_count 1m11s, day2_replace 26s, plan_approval 44s, greenfield 2m42s
corpus-security-group-complete4m53.8scold_deploy 33s, migrate 44s, test_plan 9s, test_apply 8s, drift_reconverge 13s, day2_rename 27s, day2_remove 20s, day2_count 53s, day2_replace 20s, plan_approval 36s, greenfield 30s
corpus-simpleinfra-dns12m44scold_deploy 1m32s, migrate 1m20s, test_plan 15s, test_apply 39s, drift_reconverge 32s, day2_rename 40s, day2_remove 36s, day2_count 1m15s, day2_replace 1m18s, plan_approval 1m6s, greenfield 3m30s
corpus-sqs-basic12m15scold_deploy 1m22s, migrate 2m22s, test_plan 4s, test_apply 5s, drift_reconverge 8s, day2_rename 14s, day2_remove 54s, day2_count 2m9s, day2_replace 1m19s, plan_approval 21s, greenfield 3m16s
corpus-sumaform-aws18m21.1scold_deploy 1m33s, migrate 4m0s, test_plan 27s, test_apply 26s, drift_reconverge 55s, day2_rename 1m37s, day2_remove 39s, day2_count 4m42s, day2_replace 1m53s, plan_approval 2m8s, greenfield 3m12s
corpus-vpc-complete6m39.7scold_deploy 40s, migrate 1m32s, test_plan 8s, test_apply 7s, drift_reconverge 19s, day2_rename 24s, day2_remove 29s, day2_count 1m58s, day2_replace 28s, plan_approval 33s, greenfield 58s
corpus-xancloud-iac5m6.8scold_deploy 45s, migrate 38s, test_plan 8s, test_apply 7s, drift_reconverge 17s, day2_rename 22s, day2_remove 26s, day2_count 45s, day2_replace 16s, plan_approval 31s, greenfield 51s
reference-ec2-vpc5m57scold_deploy 1m49s, migrate 41s, test_plan 4s, test_apply 5s, drift_reconverge 11s, day2_rename 19s, day2_remove 13s, day2_count 39s, day2_replace 35s, day2_crash 46s, plan_approval 25s, greenfield 10s, strict -
terralith-scale10m16.9scold_deploy 2m28s, migrate 56s, test_plan 12s, test_apply 18s, drift_reconverge 1m11s, day2_rename 31s, day2_remove 22s, day2_count 45s, day2_replace 35s, plan_approval 43s, greenfield 2m15s, strict -
corpus-cloud-platform-components14m16.7scold_deploy 1m10s, migrate 6s, test_plan 14s, test_apply 14s, drift_reconverge 27s, day2_rename 28s, day2_remove 40s, day2_count 1m41s, day2_replace 2m5s, day2_crash 3m53s, day2_teardown 26s, plan_approval 39s, greenfield 1m54s, strict 19s
corpus-govuk-cluster-access11m18.6scold_deploy 1m3s, migrate 2s, test_plan 11s, test_apply 12s, drift_reconverge 34s, day2_rename 34s, day2_remove 35s, day2_count 1m8s, day2_replace 58s, day2_crash 3m36s, day2_teardown 24s, plan_approval 34s, greenfield 1m8s, strict 18s
corpus-govuk-cluster-services11m7.5scold_deploy 1m6s, migrate 2s, test_plan 12s, test_apply 12s, drift_reconverge 37s, day2_rename 25s, day2_remove 36s, day2_count 1m12s, day2_replace 1m1s, day2_crash 3m47s, day2_teardown 25s, plan_approval 35s, greenfield 37s, strict 19s
corpus-k8s-metrics-server11m15.2scold_deploy 1m17s, migrate 3s, test_plan 11s, test_apply 11s, drift_reconverge 46s, day2_rename 23s, day2_remove 33s, day2_count 1m9s, day2_replace 56s, day2_crash 3m35s, day2_teardown 14s, plan_approval 33s, greenfield 1m11s, strict 13s
corpus-mastino-dns13m56.7scold_deploy 2m20s, migrate 54s, test_plan 9s, test_apply 21s, drift_reconverge 42s, day2_rename 41s, day2_remove 50s, day2_count 1m29s, day2_replace 1m3s, plan_approval 1m2s, greenfield 4m26s
corpus-quickpizza13m20.4scold_deploy 2m16s, migrate 2s, test_plan 12s, test_apply 12s, drift_reconverge 24s, day2_rename 24s, day2_remove 36s, day2_count 1m11s, day2_replace 1m0s, day2_crash 3m44s, day2_teardown 38s, plan_approval 35s, greenfield 1m39s, strict 25s
reference-eks-none recorded yet
reference-k8s10m37.4scold_deploy 58s, migrate 2s, test_plan 11s, test_apply 11s, drift_reconverge 23s, day2_rename 23s, day2_remove 33s, day2_count 57s, day2_replace 57s, day2_crash 3m35s, day2_teardown 25s, plan_approval 33s, greenfield 1m10s, strict 18s
reference-k8s-cert-manager45m10.4scold_deploy 2m5s, migrate 58s, test_plan 31s, test_apply 51s, drift_reconverge 1m40s, day2_rename 1m40s, day2_remove 3m41s, day2_count 5m32s, day2_replace 5m3s, day2_crash 12m31s, day2_teardown 1m29s, plan_approval 3m45s, greenfield 4m27s, strict 56s
reference-k8s-platform-app17m11.9scold_deploy 1m5s, migrate 43s, test_plan 35s, test_apply 34s, drift_reconverge 29s, day2_rename 30s, day2_remove 40s, day2_count 1m7s, day2_replace 1m16s, day2_crash 5m27s, day2_teardown 1m3s, plan_approval 40s, greenfield 1m26s, strict 45s, no_local_state 50s
reference-k8s-shared-objects16m52scold_deploy 1m5s, migrate 3s, test_plan 24s, test_apply 24s, drift_reconverge 57s, day2_rename 46s, day2_remove 47s, day2_count 1m9s, day2_replace 59s, day2_crash 3m54s, day2_teardown 1m25s, plan_approval 2m53s, greenfield 49s, strict 30s, no_local_state 45s
reference-k8s-stateful14m43.7scold_deploy 1m34s, migrate 2s, test_plan 11s, test_apply 12s, drift_reconverge 23s, day2_rename 23s, day2_remove 1m29s, day2_count 57s, day2_replace 58s, day2_crash 3m35s, day2_teardown 1m57s, plan_approval 34s, greenfield 1m24s, strict 1m4s
reference-k8s-workloads12m58.2scold_deploy 1m18s, migrate 2s, test_plan 23s, test_apply 13s, drift_reconverge 35s, day2_rename 23s, day2_remove 1m8s, day2_count 57s, day2_replace 42s, day2_crash 3m35s, day2_teardown 33s, plan_approval 34s, greenfield 1m17s, strict 19s

Live-AWS certification

A real-AWS run for the named estate, at the date and account below, is evidence about one run and never counts toward either bar. HANDOFF.md “What a measurement is worth” has why the two are never averaged.

EstateTargetRegionClearDateCeiling
reference-ec2-vpcawsus-east-2yes2026-09-08T01:17:12Z$5.00
terralith-scaleawsus-east-2no2026-09-11T12:31:25Z$100.00

To add an estate, see Add an estate.