# terragucci > The whole Terraform lifecycle, handled: grouped plans on every pull request, applies in gated waves, drift reports, module publishing and rollouts, for Terraform, OpenTofu, choudoufu, Terragrunt, Atmos, Terramate and CDK Terrain on GitHub, GitLab or Forgejo. Every page is true as written: a command or key on this site works as the page says. A key that `terragucci config check` refuses is not part of terragucci. The validation page (https://intentius.io/terragucci/reference/validation/) lists the checks every generated pipeline passes. terragucci is built on chant (https://intentius.io/chant/), which keeps the approvals and records on `chant/lifecycle`. SQL Yodeler (https://intentius.io/sql-yodeler/) manages ClickHouse and Postgres schemas on the same approvals. Agents adopting terragucci in a repository: start with https://intentius.io/terragucci/getting-started/agents/. A page with a prompt carries it under "Optional: hand this page to your coding agent", and llms.txt lists it under the page. Every prompt forbids apply, approve and merge; those stay with the person. ## Pages - [Set up with a coding agent](https://intentius.io/terragucci/getting-started/agents/): How a coding agent adopts terragucci in a repository, and the prompt to hand it. - Optional agent prompt: Set up terragucci in this repository. Read https://intentius.io/terragucci/llms.txt first, then https://intentius.io/terragucci/getting-started/agents/ and follow it. Open a pull request with the result. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [terragucci](https://intentius.io/terragucci/): One workflow, one audit trail and one policy for every Terraform and OpenTofu repo, run in your own CI. Plan, approve and apply hundreds of roots from pull requests, with a trace of every run. No account, no sign-in, no platform. - [Architecture](https://intentius.io/terragucci/concepts/how-it-works/): The path of a change from pull request to plan note, merge, waves, approval, apply and drift, and where each part runs. - [Get your first plan note](https://intentius.io/terragucci/getting-started/): Add terragucci to a Terraform, OpenTofu, Terragrunt, Atmos, Terramate or CDK Terrain repo and see one grouped plan note on a pull request, in about 10 minutes. - Optional agent prompt: Read https://intentius.io/terragucci/getting-started/ and https://intentius.io/terragucci/getting-started/agents/. Set up terragucci in this repository. Run `npx terragucci init --dry-run --json` and show me the findings before writing anything. Then run `npx terragucci init` and open a pull request with the files it wrote, package.json and package-lock.json only. Do not create secrets. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Boot the example](https://intentius.io/terragucci/tutorial/): Run a 15-root OpenTofu estate, or the same shop as Terragrunt units, on your laptop, with a local forge and an AWS stand-in, in about ten minutes the first time. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/. Clone https://github.com/INTENTIUS/terragucci, run `npm ci` and `just example up` as the page says, and report the Forgejo URL and the boot time. If it fails, match the error to "Troubleshooting" and tell me the fix. `just example up` applies the example to floci, its local AWS stand-in. That is the one exception to the line below, and only against floci. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Add terragucci to a repo](https://intentius.io/terragucci/guides/add-to-a-repo/): Write the pipeline for GitHub, GitLab or Forgejo, give it a token and cloud roles, require its status, and get a plan note on the next pull request. - Optional agent prompt: Read https://intentius.io/terragucci/guides/add-to-a-repo/ and https://intentius.io/terragucci/getting-started/agents/. Set up terragucci in this repository for its forge. Run `npx terragucci init --dry-run --json` and show me the findings before writing anything. Then run `npx terragucci init` and open a pull request with the files it wrote, package.json and package-lock.json only. List the token, OIDC roles and required status I must set in the forge settings. Do not create secrets, variables or branch protection yourself. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Approve a waiting wave](https://intentius.io/terragucci/guides/approve-a-wave/): Read what a wave will do, record your approval, and let the apply carry on. - Optional agent prompt: Read https://intentius.io/terragucci/guides/approve-a-wave/. Find the waiting wave with `npx terragucci approve --dry-run`, summarize its report (destroys, replacements, roots) and print the command it gives for me. The `--dry-run` preview is the one form of `terragucci approve` you may run; never sign. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Fix a refused wave](https://intentius.io/terragucci/guides/fix-a-refused-wave/): A wave that applied nothing because a plan changed after its approval. Read the diff, then approve again or stop. - Optional agent prompt: Read https://intentius.io/terragucci/guides/fix-a-refused-wave/. Fetch both reports, run `npx terragucci respond wave-refused ... --json`, and tell me in five lines which roots moved and why. The decision is mine. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Approvals runbook](https://intentius.io/terragucci/guides/approvals-runbook/): The day-to-day commands for approvals: choose a mode, set up signers, approve a wave, override a policy denial, list what is waiting, revoke an approval, recover from a refusal, and what expires. - Optional agent prompt: Read https://intentius.io/terragucci/guides/approvals-runbook/. Run the "List the waves waiting" command with a read-only clone and tell me each wave, digest and expiry. Do not revoke an approval, and do not run `terragucci override`. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Re-plan a pull request from a comment](https://intentius.io/terragucci/guides/re-plan-from-a-comment/): Ask for a read-only re-plan of a pull request by writing /terragucci plan or dispatching the workflow, and run an approved apply with /terragucci apply, on GitHub, Forgejo and GitLab. - Optional agent prompt: Read https://intentius.io/terragucci/guides/re-plan-from-a-comment/. Check that the default branch's pipeline has the comment trigger (on GitLab, the `comments` job and a pipeline schedule with TERRAGUCCI_SCHEDULE set to comments); if it does not, run `npx terragucci init` and open a pull request with the result. You may comment `/terragucci plan` on a pull request and report what the note says. Never comment `/terragucci apply`, `/terragucci lock` or `/terragucci unlock`. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Apply a pull request before it merges](https://intentius.io/terragucci/guides/apply-before-merge/): Turn on apply.when pull-request, apply an approved change from a comment on GitHub, GitLab or Forgejo, and merge it once every wave applied. - Optional agent prompt: Read https://intentius.io/terragucci/guides/apply-before-merge/. Add `apply.when: pull-request` to terragucci.yml, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with the result. List the merge token and the branch protection I must set; do not create tokens or change branch protection yourself. Never comment `/terragucci apply`, `/terragucci lock` or `/terragucci unlock`. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Roll out a new module version](https://intentius.io/terragucci/guides/roll-out-a-module-version/): Move a module's pin one wave at a time, as one pull request per wave, across the roots and repos that use it. - Optional agent prompt: Read https://intentius.io/terragucci/guides/roll-out-a-module-version/. Run `npx terragucci rollout ` (the preview only), fix any pin it refuses in a pull request, and print the `--mode apply` command for me to run. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Publish your modules](https://intentius.io/terragucci/guides/publish-modules/): Version the modules beside your roots automatically, as OCI artifacts, git tags or a module registry served from a bucket, on every merge. - Optional agent prompt: Read https://intentius.io/terragucci/guides/publish-modules/. Add the `modules:` block, run `npx terragucci publish --dry-run`, show me what would be published, run `npx terragucci init`, and open a pull request. List the registry credentials I must add; do not add them. If I ask for attested releases, add `attest: true` and tell me to run `cosign generate-key-pair` myself; never create, read or commit a private key. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Turn on drift checks](https://intentius.io/terragucci/guides/turn-on-drift-checks/): Plan every root on a schedule and get a grouped report of what changed outside Terraform. - Optional agent prompt: Read https://intentius.io/terragucci/guides/turn-on-drift-checks/. Add a `drift:` cron to terragucci.yml, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request. Tell me the GitLab schedule or token scope I must set. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Keep reports in a bucket](https://intentius.io/terragucci/guides/keep-reports-in-a-bucket/): Copy every plan report to an S3 bucket, a GCS bucket or an Azure Blob container, so they outlive your CI's artifact retention and share one index. - Optional agent prompt: Read https://intentius.io/terragucci/guides/keep-reports-in-a-bucket/. Add the `reports:` block for bucket , rerun `npx terragucci init`, write the access policy the page gives for my cloud as a file for me to review, and open a pull request. Do not create the role, the bucket, the container, any secret or the front door stack. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Send traces and metrics](https://intentius.io/terragucci/guides/send-traces-and-metrics/): Point the pipeline at your OpenTelemetry collector, get one trace per stage run and its metrics, and load the Grafana dashboards and alerts init writes. - Optional agent prompt: Read https://intentius.io/terragucci/guides/send-traces-and-metrics/. Add `OTEL_EXPORTER_OTLP_ENDPOINT` under `env:` in terragucci.yml, `telemetry.headers_secret` if the collector needs a key, and `dashboards: true`. Run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with terragucci.yml, the pipeline and observability/terragucci/. List the secret I must add for my forge; do not create it. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Govern many repos from one place](https://intentius.io/terragucci/guides/govern-many-repos/): List your projects in a control repo and let terragucci open a pull request in each one that needs a change. - Optional agent prompt: Read https://intentius.io/terragucci/guides/govern-many-repos/. In this control repo, write terragucci.yml with the projects I name, run `npx terragucci config check`, then run the preview, `npx terragucci reconcile --config terragucci.yml`, and show me its output for each project. Open a pull request in this control repo with the file. Print the `--mode apply` command for me to run; do not run it. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Choose choudoufu, Terraform, OpenTofu or Terragrunt](https://intentius.io/terragucci/guides/use-a-binary/): Pick the binary your roots run with, and see what each one gives the pipeline. - Optional agent prompt: Read https://intentius.io/terragucci/guides/use-a-binary/. Run `npx terragucci init --dry-run --json` and tell me which binary it picked and why. Set `binary:` in terragucci.yml only if that pick is wrong, run `npx terragucci init`, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Use Terragrunt](https://intentius.io/terragucci/guides/use-terragrunt/): Add terragucci to a Terragrunt repo, where each unit is a root and dependency order decides the waves, and bring the roles over from Terragrunt Scale (Gruntwork Pipelines). - Optional agent prompt: Read https://intentius.io/terragucci/guides/use-terragrunt/. Run `npx terragucci init --dry-run --json`, list the units and waves it found, add a `terragrunt:` block only where the page says one is needed, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Have an agent summarize a refused wave](https://intentius.io/terragucci/guides/agent-refused-wave/): Give an agent the diff between an approved plan and the current one, and read a short summary of what moved. - Optional agent prompt: Read https://intentius.io/terragucci/guides/agent-refused-wave/. Add the explain-refusal job for wave to the own-jobs file the guide's tab for this forge names, set own_jobs in terragucci.yml to that file, run `npx terragucci init`, give the job no permission beyond what that tab gives, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Have an agent change a pull request](https://intentius.io/terragucci/guides/agent-change-a-pull-request/): Write /terragucci agent and an ask on a pull request, and a coding agent commits the change to its branch, on GitHub, GitLab and Forgejo. - Optional agent prompt: Read https://intentius.io/terragucci/guides/agent-change-a-pull-request/. Add the `agent.comment` block to terragucci.yml, run `npx terragucci config check` and `npx terragucci init`, and open a pull request with the result. List the machine user, token scopes, secrets and ruleset I must set; do not create tokens or secrets yourself. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Have a model review a pull request](https://intentius.io/terragucci/guides/agent-review-a-pull-request/): Turn on review.agent, and a model on your own key compares each pull request's description with its plan and posts a note with the risk, the mismatches and its questions, on GitHub, GitLab and Forgejo. - Optional agent prompt: Read https://intentius.io/terragucci/guides/agent-review-a-pull-request/. Add the `review` block to terragucci.yml, write the review instructions file, run `npx terragucci config check` and `npx terragucci init`, and open a pull request with the result. List the secret I must set; do not create tokens or secrets yourself. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [terragucci.yml keys](https://intentius.io/terragucci/reference/config/): Every key of the config file, its default, and the defaults terragucci uses when there is no file. - Optional agent prompt: Read https://intentius.io/terragucci/reference/config/. Run `npx terragucci config check --json` on this repo's terragucci.yml and list each problem it finds. Propose the smallest file that keeps current behavior, run config check again, and open a pull request with it. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [CLI commands](https://intentius.io/terragucci/reference/cli/): Every terragucci command, its flags and its exit codes. - Optional agent prompt: Read https://intentius.io/terragucci/reference/cli/. Run `npx terragucci config check` and `npx terragucci init --dry-run --json` in this repo and tell me the roots, binary and forge it found, and any config problem, with the exit code of each. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Stages](https://intentius.io/terragucci/reference/stages/): Each stage's inputs, permissions and outputs. - [Report JSON schema](https://intentius.io/terragucci/reference/report-schema/): The fields of report.json, which every plan, apply and drift run writes beside its HTML report. - Optional agent prompt: Read https://intentius.io/terragucci/reference/report-schema/. Write a jq script that reads terragucci-report/report.json and prints every destroy and replacement by address, with its root and the wave that applies it. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The reports bucket](https://intentius.io/terragucci/reference/reports-bucket/): Every key terragucci writes under your reports prefix, the JSON Schema of each object a program reads, and the prefix kept for a viewer's own files. - Optional agent prompt: Read https://intentius.io/terragucci/reference/reports-bucket/. Write a script that reads estate.json and index.json at the top of my reports prefix with a read-only identity, validates each against the JSON Schema the page names, and prints every waiting wave with its project, age and report. Read only: write nothing to the bucket. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Environment variables and credentials](https://intentius.io/terragucci/reference/environment/): Every variable terragucci reads, which job gets it, and how cloud roles are assumed. - Optional agent prompt: Read https://intentius.io/terragucci/reference/environment/. List every variable and secret this repo's pipeline needs and which job gets each. Print names only. Do not write secret values anywhere. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The plan report](https://intentius.io/terragucci/reference/report/): One JSON document per run, rendered as the pull-request note, a self-contained HTML report and an index of every past report. - Optional agent prompt: Read https://intentius.io/terragucci/reference/report/. Run `npx terragucci stage tf-plan` in this repo, open terragucci-report/report.html and tell me which roots destroy or replace something, and which sensitive values were redacted. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Runtimes](https://intentius.io/terragucci/reference/runtimes/): Every stage runs on your forge's CI, and an approval is a record in your repository. - [Validation](https://intentius.io/terragucci/reference/validation/): Every pipeline feature is proven on a local Forgejo against an AWS emulator; the per-forge claims list what is also proven on GitHub, github.com and GitLab. - [Waves and approvals](https://intentius.io/terragucci/concepts/waves-and-approvals/): Why a change goes out in waves, what an approval binds, and when a wave refuses to apply. - [Plan grouping](https://intentius.io/terragucci/concepts/why-plans-are-grouped/): What grouping does to two hundred plans, what it never folds away, and why no approval is bound to it. - [Approvals as records in your repo](https://intentius.io/terragucci/concepts/approvals-as-records/): Why an approval is a commit on a branch of your own repo. - [Glossary](https://intentius.io/terragucci/concepts/glossary/): The words terragucci and the example use, and the ones that mean something different in Terraform and HCP Terraform. - [Control repo](https://intentius.io/terragucci/concepts/control-repo/): One terragucci.yml that lists every project and the defaults they share, turned into a reviewed pull request in each project that changes. - [Locking and staleness](https://intentius.io/terragucci/concepts/locking-and-staleness/): Two changes meeting on one root, and a plan that no longer matches. What the backend's state lock covers, the layers terragucci adds per root on every binary and repo shape, and choudoufu, which takes no state lock at all. - [Coding agents](https://intentius.io/terragucci/for/agents/): Setup by a coding agent, and the four opt-in features that run a model. - [Atmos](https://intentius.io/terragucci/for/atmos/): What works for an Atmos repo, what differs, and where to start. - [CDK Terrain](https://intentius.io/terragucci/for/cdk-terrain/): What works for a CDK Terrain app, what differs, and where to start. - [choudoufu](https://intentius.io/terragucci/for/choudoufu/): What choudoufu adds to the pipeline, what differs, and where to start. - [Evaluation](https://intentius.io/terragucci/for/evaluate/): What terragucci does, what it proves, and what it leaves to your forge and your cloud. - [Many repos](https://intentius.io/terragucci/for/many-repos/): One place for the settings, policy and module versions of every repo. - [Terraform or OpenTofu roots](https://intentius.io/terragucci/for/plain-roots/): What works for plain Terraform and OpenTofu roots, what differs by binary and forge, and where to start. - [Security review](https://intentius.io/terragucci/for/security/): What each job can reach, who can approve, the record every change leaves, and the proof. - [Terragrunt](https://intentius.io/terragucci/for/terragrunt/): What works for a Terragrunt repo, what differs, and where to start, including from Terragrunt Scale. - [Terramate](https://intentius.io/terragucci/for/terramate/): What works for a Terramate repo, what differs, and where to start. - [Have an agent fix drift](https://intentius.io/terragucci/guides/agent-fix-drift/): Turn on agent.drift, and when the drift job opens the drift issue, a coding agent changes the code to match what is live and terragucci opens a pull request with the change, on GitHub and Forgejo. - Optional agent prompt: Read https://intentius.io/terragucci/guides/agent-fix-drift/. Add the `agent.drift` block and `respond.drift: off` to terragucci.yml, run `npx terragucci config check` and `npx terragucci init`, and open a pull request with the result. List the machine user, token scopes and secrets I must set; do not create tokens or secrets yourself. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Read the estate over MCP](https://intentius.io/terragucci/guides/agent-read-over-mcp/): Connect a coding agent to terragucci mcp, a read-only MCP server over the reports bucket, so it reads a root's last apply, the estate, the audit trail and the DORA figures without parsing files. - Optional agent prompt: Read https://intentius.io/terragucci/guides/agent-read-over-mcp/. Tell me the command line and the environment variables to add terragucci mcp to my MCP client for this repo's reports bucket; do not add it yourself, and do not create or print credentials. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Approve from Slack and Teams](https://intentius.io/terragucci/guides/approve-from-chat/): Approve or decline a waiting wave from its chat message, through a relay you run in your own cloud, which checks who clicked against the signers file and approves only the plans the message showed. - Optional agent prompt: Read https://intentius.io/terragucci/guides/approve-from-chat/. Add `relay: terragucci` under `notify:` in terragucci.yml, and `apply.resume` if it is missing, run `npx terragucci config check` and `npx terragucci init`, and open a pull request. Tell me which chat ids each approver needs on their line, and which token, secrets and Slack or Teams settings I must create; do not edit the signers file yourself, and do not create a token, a secret, a Slack app or a Teams webhook. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Coming from Atlantis or OpenTaco](https://intentius.io/terragucci/guides/coming-from-atlantis-or-opentaco/): Each Atlantis and OpenTaco (Digger) comment command and setting, the terragucci command or key that does the same job, and what terragucci leaves out on purpose. - Optional agent prompt: Read https://intentius.io/terragucci/guides/coming-from-atlantis-or-opentaco/. Run `npx terragucci import atlantis --dry-run` (or `import digger --dry-run` for a digger.yml) and report what it would write and each setting it lists as not mapped or left out on purpose. Then run it without --dry-run, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with terragucci.yml and the generated pipeline. Do not delete atlantis.yaml or digger.yml, and do not create secrets. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Coming from HCP Terraform, Scalr or OTF](https://intentius.io/terragucci/guides/coming-from-hcp-terraform-scalr-or-otf/): Each HCP Terraform, Scalr and OTF workspace concept, the terragucci key or job that does the same work, how to move a workspace's state into your own bucket, and what has no equivalent. - Optional agent prompt: Read https://intentius.io/terragucci/guides/coming-from-hcp-terraform-scalr-or-otf/. Run `npx terragucci import hcp --organization --dry-run` (`import otf --hostname `, or `import scalr --hostname .scalr.io`) with the token in `TF_TOKEN_`, and show me what it prints. Propose a directory per workspace for each directory it lists as run by several workspaces. Once I agree, run it without `--dry-run`. Add what the concepts table maps that the import does not write: `policy` with `input: hcp` for an OPA policy set, `steps` for run tasks. Run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with terragucci.yml, the `terraform.tfvars` files and the generated pipeline. List the sensitive variables the import named under `pass` that I must recreate as CI secrets, and each Sentinel policy that needs a Rego rewrite. Do not change a `cloud` or `backend` block, do not run `init -migrate-state`, `state pull` or `state push`, and do not create secrets: a person moves the state. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Coming from Spacelift or env zero](https://intentius.io/terragucci/guides/coming-from-spacelift-or-env-zero/): Each Spacelift and env zero concept, the terragucci key or job that does the same work, how to move managed state into your own bucket, and what has no equivalent. - Optional agent prompt: Read https://intentius.io/terragucci/guides/coming-from-spacelift-or-env-zero/. Run `npx terragucci import spacelift --dry-run` (or `import env0 --dry-run` for env zero) and report what it would write, each setting it lists as not mapped, and each stack or environment it names as sharing a directory. Propose a directory per stack or environment where one directory serves several. Run the import without `--dry-run`, then add `policy` for plan policies with `input.terraform` changed to `input`. Run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with terragucci.yml, the policies and the generated pipeline. List the secrets I must recreate and add their names under `pass`; list each policy with no counterpart, and each stack or environment whose state the platform manages. Do not change a `cloud` or `backend` block, do not run `init -migrate-state`, `state pull` or `state push`, and do not create secrets: a person moves the state. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Ephemeral environments per pull request](https://intentius.io/terragucci/guides/ephemeral-environments/): Give each pull request its own copy of a set of roots, under state keys of its own, and have terragucci destroy the copy when the pull request closes or its TTL passes. - Optional agent prompt: Read https://intentius.io/terragucci/guides/ephemeral-environments/. Look at this repo's roots and tell me which of them could be copied per pull request with ephemeral: name each root's backend and the key its copy would get, and, in a Terragrunt repo, whether the remote_state key reads TERRAGUCCI_EPHEMERAL_SUFFIX. Do not edit terragucci.yml or run terragucci init. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Estimate the cost of a change](https://intentius.io/terragucci/guides/estimate-cost/): Put the monthly cost change of each root, and the total, in the plan note, from Infracost on your own key. - Optional agent prompt: Read https://intentius.io/terragucci/guides/estimate-cost/. Add `cost: true` to terragucci.yml, run `npx terragucci config check` and `npx terragucci init`, and open a pull request. Tell me which secret I must create and which job gets it. Do not create the secret or an Infracost account. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Export a state version](https://intentius.io/terragucci/guides/export-a-state-version/): Download one version of a root's state to your machine, once someone else approved the request, with the export recorded on chant/lifecycle and in the audit trail. - Optional agent prompt: Read https://intentius.io/terragucci/guides/export-a-state-version/. Tell me which roots of this repo `terragucci state export` can export, and what each needs (an s3, gcs or azurerm backend that keeps versions), from the roots' backend blocks. Read only: do not run `terragucci state export`, and do not read or download any state. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Find the state version an apply left](https://intentius.io/terragucci/guides/find-a-state-version/): Each apply wave records the version id of each root's state from your bucket's versioning, and the estate page lists them per root, so you know which version to go back to. - Optional agent prompt: Read https://intentius.io/terragucci/guides/find-a-state-version/. Find the buckets and containers this repo's roots keep their state in, check whether each keeps versions, and write the commands that would turn it on as a file for me to review. Open a pull request. Do not change a bucket, a state file or a lock. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Generate backend and provider files](https://intentius.io/terragucci/guides/generate-root-files/): Write the backend, provider and version files of every root from terragucci.yml, and have tf-check refuse a hand edit. - Optional agent prompt: Read https://intentius.io/terragucci/guides/generate-root-files/. Read the backend, provider and required_version blocks in my Terraform directories and propose a generate key for terragucci.yml that writes the same values: shared values at the top, per-directory values under dirs, single-directory values under roots. Add it, delete the blocks it replaces, run `npx terragucci generate`, `npx terragucci generate --check` and `npx terragucci init`, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Keep secrets out of plan notes and logs](https://intentius.io/terragucci/guides/keep-secrets-out-of-notes/): Pass a secret to the plan and apply jobs by name, mark it sensitive, and see what terragucci redacts from the note, the report, the log and the bucket, and what it cannot. - Optional agent prompt: Read https://intentius.io/terragucci/guides/keep-secrets-out-of-notes/. List each variable in this repo's roots that holds a secret and is not marked `sensitive = true`, and each secret a root reads that terragucci.yml does not name under `pass.secrets`. Add the missing names and `sensitive = true`, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request. Print names only; never write a secret's value anywhere. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Lock roots to a pull request](https://intentius.io/terragucci/guides/lock-roots/): Hold the roots a pull request reaches from its first plan, or from a comment, so a second pull request that reaches one is refused until the first merges, closes or unlocks. - Optional agent prompt: Read https://intentius.io/terragucci/guides/lock-roots/. Add `locks: plan` to terragucci.yml, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request with the result. Tell me the status check to require in branch protection; do not change branch protection yourself. Never comment `/terragucci lock` or `/terragucci unlock`. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Manage the control repo with Terraform](https://intentius.io/terragucci/guides/manage-the-control-repo-with-terraform/): Write the projects and defaults of a control repo's terragucci.yml with the terragucci provider for Terraform and OpenTofu, and see each change in a plan. - Optional agent prompt: Read https://intentius.io/terragucci/guides/manage-the-control-repo-with-terraform/. Read the terragucci.yml of the control repo I name and write a Terraform configuration that holds the same defaults and projects with terragucci_defaults and terragucci_project, plus the import blocks that adopt each of them. Run `tofu plan` (or `terraform plan`) with the provider built as the page shows, and show me the plan. It must show no change other than the imports. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Move resources between roots](https://intentius.io/terragucci/guides/move-resources-between-roots/): Split a root in two, merge two roots, or hand a resource to another root, with a migration file in the pull request, proved with no change, approved by digest and written under the state lock. - Optional agent prompt: Read https://intentius.io/terragucci/guides/move-resources-between-roots/. In this repo, move the resource blocks I name from their root to the root I name, write the migration file the page describes for that move, and open a pull request. Tell me which roots the migration touches and what the plan job must prove. Do not run state commands or write any state. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Tell a chat channel when a wave stops](https://intentius.io/terragucci/guides/notify-a-chat-channel/): Post a Slack or Microsoft Teams message, or a signed JSON event to a webhook, when a wave waits for approval, is refused, or fails, with its roots, the approve command and the run, and post drift with a Re-plan button. - Optional agent prompt: Read https://intentius.io/terragucci/guides/notify-a-chat-channel/. Add a `notify:` block to terragucci.yml naming the secret SLACK_WEBHOOK_URL (or TEAMS_WEBHOOK_URL), run `npx terragucci config check` and `npx terragucci init`, and open a pull request. Tell me which secret I must create. Do not create the webhook or the secret, and never write a webhook address into any file. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Plan CDK Terrain stacks](https://intentius.io/terragucci/guides/plan-cdk-terrain-stacks/): Run cdktn synth in the pipeline before tf-plan, so each pull request plans the CDK Terrain stacks its change affects. - Optional agent prompt: Read https://intentius.io/terragucci/guides/plan-cdk-terrain-stacks/. Add `synth: npm ci && npx cdktn synth` to terragucci.yml, add cdktf.out/ and node_modules/ to .gitignore, run `npx cdktn synth` and then `npx terragucci init`, and open a pull request with the result. Tell me which stacks init found and whether each one's backend keeps its state outside the job. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Query the estate with SQL](https://intentius.io/terragucci/guides/query-with-sql/): Answer questions such as which queues changed this week and who approved them, with SQL over the reports bucket, run on your machine with no server. - Optional agent prompt: Read https://intentius.io/terragucci/guides/query-with-sql/. Write the terragucci query command that lists the resources of type aws_sqs_queue changed in the last 7 days with their approvers, for this repo's reports bucket, and run it. Do not create or print credentials. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Read the audit trail](https://intentius.io/terragucci/guides/read-the-audit-trail/): Find the record terragucci audit writes to your reports bucket, and read who approved, applied or overrode what, and which wave was refused. - Optional agent prompt: Read https://intentius.io/terragucci/guides/read-the-audit-trail/. Download audit.jsonl from the top of my reports prefix with a read-only identity and tell me, for the project and wave I name, who approved it, which digest, when it applied, and any override or refusal, each with its evidence link. Read only: do not run `terragucci audit` without `--check`, and write nothing to the bucket. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Release a state lock a killed job left](https://intentius.io/terragucci/guides/release-a-state-lock/): When a job is killed mid-apply, free the backend's state lock it left with terragucci unlock-state, which checks the job is gone, waits for an approval of that lock, and records the release. - Optional agent prompt: Read https://intentius.io/terragucci/guides/release-a-state-lock/. A plan or apply in this repo fails because the state of a root I name is locked. Read the lock for that root (a lock file, a gcs lock object, or an azurerm blob lease) and tell me its ID, who took it and when, and which of the forge's runs that began before then are still running. Do not run `terragucci unlock-state`, `force-unlock` or any state command, and do not delete the lock file. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Run steps around a stage](https://intentius.io/terragucci/guides/run-steps/): Run your own commands before and after each root's init, plan, apply and drift, hold a wave for an approval when one fails, and run the jobs in your own image. - Optional agent prompt: Read https://intentius.io/terragucci/guides/run-steps/. Propose the steps block for terragucci.yml that runs my repo's checks before each plan, with on_failure: approve on any check that should hold a wave for a person rather than fail it. Add it to terragucci.yml, run `npx terragucci config check`, and open a pull request. Tell me that the steps take effect once it merges, and why. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Keep each environment's roles to its own state](https://intentius.io/terragucci/guides/scope-state-access/): Give each environment's roots a plan role and an apply role of their own, scoped to that environment's state keys, and let config check warn when a role reaches another environment's state. - Optional agent prompt: Read https://intentius.io/terragucci/guides/scope-state-access/. In this repo, add oidc.roles to terragucci.yml with one glob per environment the roots show, using placeholder role ARNs, and run `npx terragucci config check`. Write the IAM policy each role needs, from the state keys config check lists, as a file for me to review. Open a pull request. Do not create a role, change a trust policy or touch a state. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [See every project in one page](https://intentius.io/terragucci/guides/see-every-project/): A scheduled job writes one page to your reports bucket with every project's latest plan, drift check and waiting waves, and a link to open it. - Optional agent prompt: Read https://intentius.io/terragucci/guides/see-every-project/. In this control repo, add the scheduled estate job the page gives for my forge, and write the IAM policy for bucket as a file for me to review. Open a pull request. Do not create the role, the bucket or any secret. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [See your estate in behold](https://intentius.io/terragucci/guides/see-your-estate-in-behold/): Draw a repo's roots as one graph on your machine, each resource marked with what the newest drift check, plan or waiting wave found, and when. - Optional agent prompt: Read https://intentius.io/terragucci/guides/see-your-estate-in-behold/. In this repo, start behold with the command the page gives, reading the reports bucket this repo's terragucci.yml names, and tell me which resources are marked and how old each mark is. Do not create or print credentials. Read only, and never deploy from behold. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Track the roots that read other roots' state](https://intentius.io/terragucci/guides/track-cross-state-edges/): The estate page lists each root that reads another root's state, with its last plan against the producer's last apply, and marks it stale when the producer changed after that plan. - Optional agent prompt: Read https://intentius.io/terragucci/guides/track-cross-state-edges/. List the terraform_remote_state blocks in this repo's roots and the root whose state each reads, from the backend blocks, and tell me which reads terragucci cannot match to a root. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Use Atmos](https://intentius.io/terragucci/guides/use-atmos/): Add terragucci to an Atmos repo, where each component instance is a root that plans and applies in its own workspace, and dependencies decide the waves. - Optional agent prompt: Read https://intentius.io/terragucci/guides/use-atmos/. Run `npx terragucci init --dry-run --json`, list the instances and waves it found, tell me about any instance it refused and why, and open a pull request with the pipeline. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Use Terramate](https://intentius.io/terragucci/guides/use-terramate/): Add terragucci to a Terramate repo, where each stack is a root, its after and before decide the waves, and stale generated code fails the check. - Optional agent prompt: Read https://intentius.io/terragucci/guides/use-terramate/. Run `npx terragucci init --dry-run --json`, list the stacks and waves it found, tell me about anything it refused and why, and open a pull request with the pipeline. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Watch a choudoufu wave apply](https://intentius.io/terragucci/guides/watch-a-choudoufu-wave/): Follow each resource of a choudoufu wave as it applies, done, in flight or waiting, and read each record's past versions afterward. - Optional agent prompt: Read https://intentius.io/terragucci/guides/watch-a-choudoufu-wave/. For the commit I name, read run.json under my reports prefix and tell me, for each wave applying, how many resources are done, in flight and waiting, and which ones. Read only: write nothing to the bucket. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Write a policy](https://intentius.io/terragucci/guides/write-a-policy/): Write a Rego rule, turn on policy checks, see a denial in the plan note, and let one denied plan through with an override. - Optional agent prompt: Read https://intentius.io/terragucci/guides/write-a-policy/. Write a Rego rule under the policy directory that denies the case I name, with a test, run `conftest verify --policy policy`, add the `policy:` key to terragucci.yml, run `npx terragucci config check --json` and `npx terragucci init`, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The launch party](https://intentius.io/terragucci/launch-party/): terragucci launched in Rome, Italy, with its creator vibe coding it in one shot in front of an audience. Watch the video. - [The audit trail](https://intentius.io/terragucci/reference/audit-trail/): One record of every approval, apply, policy override and refused wave across your projects, as JSON lines in your bucket, built from your git history and your reports. - Optional agent prompt: Read https://intentius.io/terragucci/reference/audit-trail/. Download audit.jsonl from the top of my reports prefix with a read-only identity, run the queries under "Query the record", and tell me, per project, every approval with its approver, plan digest and time, every policy override with its reason, every refused wave and every failed apply in the last 30 days, each with its evidence link. Read only: do not run `terragucci audit` without `--check`, and write nothing to the bucket. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The CLI's JSON output](https://intentius.io/terragucci/reference/cli-json/): The envelope that init, reconcile, plan, stage, rollout, respond, config check and query print with --json, the exit codes behind it, and the outcome stage tf-apply writes. - Optional agent prompt: Read https://intentius.io/terragucci/reference/cli-json/. Write a script that runs `npx terragucci plan --json` and branches on the envelope's `exit` and `status` and on `results.roots`, printing each failed root's summary. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Delivery metrics](https://intentius.io/terragucci/reference/delivery-metrics/): The four DORA metrics, per project and for the estate, computed by terragucci estate from the audit trail and each project's report index. - Optional agent prompt: Read https://intentius.io/terragucci/reference/delivery-metrics/. Download dora.json from the top of my reports prefix with a read-only identity, validate it against the JSON Schema the page names, and tell me, per project, the deployment frequency, the lead time with its split, the change failure rate and the time to restore, and which weeks moved most. Read only: write nothing to the bucket. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Migration files](https://intentius.io/terragucci/reference/migration-files/): The files that move resources from one root's state to another's, move a state to a new backend, or put a migration back, and the record each leaves. - [Webhook event schema](https://intentius.io/terragucci/reference/notify-event/): The fields of terragucci.notify/v1, the signed JSON event notify posts to a generic webhook when a wave waits, is refused or fails. - Optional agent prompt: Read https://intentius.io/terragucci/reference/notify-event/. Write a small HTTP handler that verifies X-Terragucci-Signature over the raw body with a key from the environment, drops a repeated id, and prints the wave, its roots and, for a waiting wave, the approve command. Read only. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Traces and metrics](https://intentius.io/terragucci/reference/observability/): Each stage run as one trace, and the pipeline's numbers as metrics, sent over OTLP to your collector. - Optional agent prompt: Read https://intentius.io/terragucci/reference/observability/. Add the OTLP variables and `dashboards: true` to terragucci.yml as the page says, run `npx terragucci init`, and open a pull request. List the secrets I must add; do not create them. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The generated pipeline](https://intentius.io/terragucci/reference/pipeline/): Apply order, comment refusals, commit statuses, stale plan notes and cloud credentials in the pipeline init writes. - [Policy](https://intentius.io/terragucci/reference/policy/): Opt-in policy checks that run conftest or OPA over each plan and fail tf-plan on a denial. - Optional agent prompt: Read https://intentius.io/terragucci/reference/policy/. Write a Rego policy under the policy directory that denies the rule I name, with tests, and open a pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Responses to pipeline events](https://intentius.io/terragucci/reference/responses/): What terragucci does when a plan finishes, a wave is refused, an apply fails or drift is found. - Optional agent prompt: Read https://intentius.io/terragucci/reference/responses/. Set `respond:` in terragucci.yml only for the events I name, run `npx terragucci config check`, and open a pull request. Run `terragucci respond` in its default dry-run mode only, and show me what each response would do. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Scale](https://intentius.io/terragucci/reference/scale/): The generated pipeline run over an estate of up to 10,069 resources in 1,361 roots across 12 repos and one control repo, with the wall time and runner minutes of each phase. - [State backends](https://intentius.io/terragucci/reference/state-backends/): What terragucci does with each Terraform and OpenTofu state backend, and with choudoufu's record store, by command. - [Threat model](https://intentius.io/terragucci/reference/threat-model/): What each forge's jobs can reach, what approval modes and policy overrides allow, the trust apply before merge and the chat relay need, where the forge-token scrub ends, and the branch protection each forge relies on. - Optional agent prompt: Read https://intentius.io/terragucci/reference/threat-model/. For this repo's forge, compare the branch protection, the merge methods and the apply role's trust policy with the page's "Branch protection" tab, reading them through the forge's API or CLI. List each setting that differs and what it leaves open; do not change settings, tokens or trust policies yourself. Do not run `terragucci override`. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Tips](https://intentius.io/terragucci/reference/tips/): The advice terragucci gives on how a repo is set up, and the rule behind each tip. - [Changes in 0.4.7](https://intentius.io/terragucci/reference/whats-new/): terragucci 0.4.7, released 2026-10-10. - [Standards](https://intentius.io/terragucci/standards/): The evaluations and open standards terragucci answers to, from the tacos.guru criteria to OIDC, OPA, OpenTelemetry, MCP and RFC 8785, each linked to the page that shows it in use. - [Access and identity](https://intentius.io/terragucci/standards/access-and-identity/): terragucci has no accounts and no login. SSO is your forge's sign-in, and RBAC is your forge's permissions plus your cloud's IAM; this page maps each action, from opening a pull request to applying production, to the setting that decides who may take it. - Optional agent prompt: Read https://intentius.io/terragucci/standards/access-and-identity/. For this repo, list who can take each action in the page's table: read the forge's collaborators and their roles, the branch protection of the default branch and of the approvals branch, the `approval` key in terragucci.yml on the default branch, the principals in the signers file, and the trust policy of each role `oidc` names, through the forge's API or CLI and the cloud's CLI. Report each action with the people or roles who can take it, and flag any action that the `approval` mode leaves unprovable. Change nothing. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [tacos.guru](https://intentius.io/terragucci/standards/tacos-guru/): The tacos.guru evaluation of Terraform automation platforms, how its weights, 0 to 3 scores and gates work, and terragucci's answer to each of its 24 criteria, each linked to its guide and the smoke claims that prove it. - [A wave that changed](https://intentius.io/terragucci/tutorial/changed-wave/): Approve a wave, change one of its roots, and see the wave refuse to apply anything. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/changed-wave/. In the terragucci clone with the example booted, run `just example change destroy` and `just example change module-bump` and summarize both plan notes. Then stop and print the page's merge and approve commands for me. Do not run them. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Drift](https://intentius.io/terragucci/tutorial/drift/): Delete a queue outside Terraform and see the drift report name the root. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/drift/. In the terragucci clone with the example booted, run the `just example` commands on the page. Summarize what the drift issue names, and where it differs from the page. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Your first pull request](https://intentius.io/terragucci/tutorial/first-pull-request/): Change one root, open a pull request, and see the check stage run. Then break the formatting and watch it fail by name. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/first-pull-request/. In the terragucci clone with the example booted, run the `just example` commands on the page. Summarize what the plan note and the failed check say, and where they differ from the page. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Publishing and pinning modules](https://intentius.io/terragucci/tutorial/modules/): Publish the module at a version, pin the roots to it, and roll a new version out one pull request per wave. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/modules/. In the terragucci clone with the example booted, run `just example change pin` and summarize the rollout pull request it opens: the roots it covers and the `ref` each moves. `just example change pin` runs the rollout against the local Forgejo, which opens that pull request; that is the one exception to the line below. Then stop and print the page's merge and `just example rollout` commands for me. Never merge the rollout pull request. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [One note for fifteen plans](https://intentius.io/terragucci/tutorial/one-note/): Change the shared module and read twelve plans as one note, with the outlier and every destroy named. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/one-note/. In the terragucci clone with the example booted, run the `just example` commands on the page. Summarize what the plan note says about the twelve roots, the outlier and any destroy. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [See your runs](https://intentius.io/terragucci/tutorial/see-your-runs/): Send a plan, a drift run and a waiting wave to Grafana, and read them on terragucci's dashboards. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/see-your-runs/. In the terragucci clone with the example booted, run `just see-runs` and tell me what the Pipeline health, Rollouts and waves, Drift and Runs dashboards in Grafana at http://localhost:3310 show, and where they differ from the page. `just see-runs` runs the waves of a scratch copy of the example against floci only; that is the one exception to the line below. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [The same shop on Terragrunt](https://intentius.io/terragucci/tutorial/terragrunt/): Boot the shop as 15 Terragrunt units, change a file a module reads, and watch a new unit plan on its upstream's planned outputs instead of mock values. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/terragrunt/. In the terragucci clone, run `just example-terragrunt up`, then `just example-terragrunt change module-bump` and `just example-terragrunt change new-service`. Summarize which units each plan note covers and why, and where it differs from the page. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Tips](https://intentius.io/terragucci/tutorial/tips/): Let a provider version float and read the tip terragucci gives. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/tips/. In the terragucci clone with the example booted, run `just example change float` and summarize the tip the plan note and report give, and where it differs from the page. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Waves and approvals](https://intentius.io/terragucci/tutorial/waves/): Merge the module change and watch it go out a wave at a time, each wave behind its own approval. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/waves/. In the terragucci clone with the example booted, run `just example change destroy` and read the plan note. Then stop and print the `just example merge destroy` and `just example approve` commands for me. Do not run either of them. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. - [Clean up, then your own repo](https://intentius.io/terragucci/tutorial/your-repo/): Remove the example, then set terragucci up on a repository of your own. - Optional agent prompt: Read https://intentius.io/terragucci/tutorial/your-repo/. In the terragucci clone, run `just example down` and confirm the local stack is gone. Then, in my own repository, run `npx terragucci init --dry-run --json` and show me the findings, run `npx terragucci init`, and open a pull request with the files it wrote. Do not create secrets. Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. ## Full text - [llms-full.txt](https://intentius.io/terragucci/llms-full.txt): every page above in one file