Skip to content

See your estate in behold

llms.txtlists every page for an agent
Optional: hand this page to your coding agentThe steps work by hand too.
Show the whole prompt
Read https://intentius.io/terragucci/guides/see-your-estate-in-behold/.
In this repo, start behold with the command the page gives, reading the reports bucket this repo's terragucci.yml names, and tell me which resources are marked and how old each mark is. Do not create or print credentials.
Read only, and never deploy from behold. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.

The estate page counts per project. behold draws one repo’s roots and resources as a graph and marks each resource with what your runs last found about it. It runs on your machine against the checkout and the reports bucket. Nothing is written, and the pipeline never needs it.

Terminal window
npx --yes -p @intentius/behold@0.25.0 -p @intentius/chant-lexicon-terraform@^0.121.0 -p @cdktn/hcl2json@^0.24.0 \
behold serve . --terragucci s3://acme-terragucci/reports

Use the bucket and prefix from your terragucci.yml, then open http://127.0.0.1:4600. Each root is a box of its resources. A resource a run flagged carries a mark with the time that run finished, and the Terragucci tab lists every root with its newest drift check, plan and apply wave.

Mark Means From
⚠ drift the newest drift check found the resource changed or deleted outside Terraform, or existing outside the state the root’s newest tf-drift report
~ plan the newest plan that holds the root would change the resource, with its pull request the root’s newest tf-plan report
⏸ wave a wave waiting for an approval would change the resource the waiting tf-apply wave’s report

Each card’s corner says how old its newest mark is. Click a card to list its marks with the finish time and report of each run. A mark is what a run saw when it ran, and nothing on the page is a live read. A card with no mark is one no report names; it may still differ from the cloud. A root no run planned says “no report”.

When the bucket holds estate.json, behold shows the estate page’s own counts.

A waiting wave lists its roots and what it destroys or replaces. It says how long it has waited and gives the line to approve it:

Terminal window
npx terragucci approve wave-2 --plan jcs1-sha256:2e0f...

behold has no approve button. Run the line in your shell, which records the approval on chant/lifecycle against that plan digest, as in Approve a wave. In a repo with a terragucci.yml, behold refuses to deploy or approve or start a run.

You need Why
Node.js 20 or later npx runs terragucci and behold
a checkout of the repo behold draws the roots from its Terraform files
reports in a bucket the marks come from the reports there
read access to the bucket, or a copy of the prefix behold reads the reports with your own credentials
  1. Give your shell read access to the reports. behold reads an S3 prefix with your AWS profile. A read-only identity needs s3:GetObject on these keys:

    <prefix>/*index.json
    <prefix>/*/report.json
    <prefix>/estate.json

    For a GCS or Azure bucket, set reports.url, or copy the prefix to a directory with gcloud storage rsync or azcopy.

  2. From the repo’s root, run the command under Result. To read a copy instead of the bucket, pass the directory:

    Terminal window
    aws s3 sync s3://acme-terragucci/reports ./reports
    npx --yes -p @intentius/behold@0.25.0 -p @intentius/chant-lexicon-terraform@^0.121.0 -p @cdktn/hcl2json@^0.24.0 \
    behold serve . --terragucci ./reports
  3. If the bucket holds several repos and none matches this checkout’s git remote, add --terragucci-project github.com/acme/infra.

  4. Stop it with Ctrl-C. behold binds 127.0.0.1 only.

  • behold 0.25.0 reads repos whose chant.workspace.json asks for minReader 0.121.0 or older; terragucci init writes 0.102.0. It refuses a repo that asks for a newer reader.
  • A malformed index.json, report.json or estate.json is refused with what to fix, rather than drawn.
  • A control repo has no roots of its own, so behold draws nothing there. Serve each project’s repo.

For a link the team can open without running anything, the estate job can publish a static view next to the estate page: see A resource graph beside the page. behold is never hosted as a shared server.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.