See your estate in behold
Optional: hand this page to your coding agentThe steps work by hand too.Show the whole prompt
Read https://intentius.io/terragucci/guides/see-your-estate-in-behold/.
In this repo, start behold with the command the page gives, reading the reports bucket this repo's terragucci.yml names, and tell me which resources are marked and how old each mark is. Do not create or print credentials.
Read only, and never deploy from behold. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.The estate page counts per project. behold draws one repo’s roots and resources as a graph and marks each resource with what your runs last found about it. It runs on your machine against the checkout and the reports bucket. Nothing is written, and the pipeline never needs it.
Result
Section titled “Result”npx --yes -p @intentius/behold@0.25.0 -p @intentius/chant-lexicon-terraform@^0.121.0 -p @cdktn/hcl2json@^0.24.0 \
behold serve . --terragucci s3://acme-terragucci/reportsUse the bucket and prefix from your terragucci.yml, then open http://127.0.0.1:4600. Each root is a box of its resources. A resource a run flagged carries a mark with the time that run finished, and the Terragucci tab lists every root with its newest drift check, plan and apply wave.
| Mark | Means | From |
|---|---|---|
| ⚠ drift | the newest drift check found the resource changed or deleted outside Terraform, or existing outside the state | the root’s newest tf-drift report |
| ~ plan | the newest plan that holds the root would change the resource, with its pull request | the root’s newest tf-plan report |
| ⏸ wave | a wave waiting for an approval would change the resource | the waiting tf-apply wave’s report |
Each card’s corner says how old its newest mark is. Click a card to list its marks with the finish time and report of each run. A mark is what a run saw when it ran, and nothing on the page is a live read. A card with no mark is one no report names; it may still differ from the cloud. A root no run planned says “no report”.
When the bucket holds estate.json, behold shows the estate page’s own counts.
Waiting waves
Section titled “Waiting waves”A waiting wave lists its roots and what it destroys or replaces. It says how long it has waited and gives the line to approve it:
npx terragucci approve wave-2 --plan jcs1-sha256:2e0f...behold has no approve button. Run the line in your shell, which records the approval on chant/lifecycle against that plan digest, as in Approve a wave. In a repo with a terragucci.yml, behold refuses to deploy or approve or start a run.
Prerequisites
Section titled “Prerequisites”| You need | Why |
|---|---|
| Node.js 20 or later | npx runs terragucci and behold |
| a checkout of the repo | behold draws the roots from its Terraform files |
| reports in a bucket | the marks come from the reports there |
| read access to the bucket, or a copy of the prefix | behold reads the reports with your own credentials |
-
Give your shell read access to the reports. behold reads an S3 prefix with your AWS profile. A read-only identity needs
s3:GetObjecton these keys:<prefix>/*index.json<prefix>/*/report.json<prefix>/estate.jsonFor a GCS or Azure bucket, set
reports.url, or copy the prefix to a directory withgcloud storage rsyncorazcopy. -
From the repo’s root, run the command under Result. To read a copy instead of the bucket, pass the directory:
Terminal window aws s3 sync s3://acme-terragucci/reports ./reportsnpx --yes -p @intentius/behold@0.25.0 -p @intentius/chant-lexicon-terraform@^0.121.0 -p @cdktn/hcl2json@^0.24.0 \behold serve . --terragucci ./reports -
If the bucket holds several repos and none matches this checkout’s git remote, add
--terragucci-project github.com/acme/infra. -
Stop it with Ctrl-C. behold binds
127.0.0.1only.
Limits
Section titled “Limits”- behold 0.25.0 reads repos whose
chant.workspace.jsonasks forminReader0.121.0 or older;terragucci initwrites 0.102.0. It refuses a repo that asks for a newer reader. - A malformed
index.json,report.jsonorestate.jsonis refused with what to fix, rather than drawn. - A control repo has no roots of its own, so behold draws nothing there. Serve each project’s repo.
Share a view
Section titled “Share a view”For a link the team can open without running anything, the estate job can publish a static view next to the estate page: see A resource graph beside the page. behold is never hosted as a shared server.
- Approve a wave runs the approve line.
- The reports bucket lists the files behold reads.
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.