hand-written reference project: the plainest getting-started shape (VPC/subnet/SG/IGW/EC2)

Set: core. Lane: reference.

Why it is in the core set: the plainest hand-written reference shape, kept in this repository

Not clear yet.

StageVerdictDetail
Cold deploypass5 resources from plain terraform, a real terraform.tfstate, zero markers
Migratepass5 of 5 verified, 5 stamped, 0 skipped
Replan from nothingpasspost-adoption plan is empty; markers read back through the AWS CLI in part A
No-op applypassno-op apply (0 added, 0 changed, 0 destroyed); tofu-estate-tagged object count unchanged at 5
Drift and reconvergepassone object tampered, exactly aws_instance.main proposed, apply changed 1 and the tag reads back as configured
Renamepassmoved block: aws_security_group renamed with zero churn (0 add, 1 change, 0 destroy), marker rewritten in place; live-mv: aws_internet_gateway renamed with zero churn, marker rewritten in place; stock oracle over the same two-resource rename on cold_deploy’s own state also shows zero churn (0 add, 0 change, 0 destroy); both live ids unchanged, read via the AWS CLI
Remove a blockpasschoudoufu: deleting aws_internet_gateway.renamed’s block proposed exactly one destroy (0 add, 0 change, 1 destroy), applied cleanly (0 added, 0 changed, 1 destroyed), the object is genuinely gone from the live account (describe-internet-gateways on the old id no longer returns it, read via the AWS CLI, not choudoufu’s own report), and the next plan is empty; stock oracle on cold_deploy’s own state (B1.6) also proposes exactly one destroy for the same object; classifyOrphans did not withhold the destroy because no other aws_internet_gateway block is declared anywhere in this config
Change count (planned)FAILchoudoufu’s scale-down plan does not destroy count_test[1]
Replace with create_before_destroynot run
Crash between create and destroy (planned)not run
Teardown (planned)not run
Plan, review, apply (planned)not run
Greenfield applypass5-object structural comparison (vpc/subnet/igw/sg/instance) between the greenfield estate and stock’s cold deploy matches, via the AWS CLI on both endpoints, marker tags never compared; local record store held 5 records, one per instance (#364 A2); replanned empty both with and without the local record store
Strict profile (planned)not run

Last run at commit 10e3f76bcd on 2026-08-25T18:04:37Z, exit code 1.

Verified end-to-end 2026-08-17/18. Drift-and-reconverge added 2026-08-18: the adopted estate’s EC2 instance Name tag is tampered directly via the AWS CLI against the running floci container, choudoufu plan proposes fixing exactly aws_instance.main and nothing else, and apply reconverges it - verified with a real clean run and a real BREAK=1 run (BREAK also tampers a second object’s Name tag, and the single-object assertion is confirmed to fail when it does).

Reproduce it#

go run ./tools/gauntlet run reference-ec2-vpc

Needs Docker (the emulator is pulled at the pinned digest), the AWS CLI, and a stock terraform or tofu binary on PATH for the cold deploy. The script is live/e2e/reference-ec2-vpc/run.sh; BREAK=1 corrupts its assertions to show they are load-bearing.