Skip to content

Scale

llms.txtlists every page for an agent

The bench operates about 10,000 resources in a dozen repos through the CI jobs terragucci generates. It uses no server and one modest runner.

It can. The largest run, 10,069 resources in 1,361 roots across 12 repos, took 120 minutes end to end, reconcile included, and 287 runner minutes on one runner taking 3 jobs at once. That includes a change to every root, planned with one plan note per repo and applied. It ran on a build of terragucci just after 0.4.1.

The chart gives the CI time and runner minutes to expect at your estate’s size.

The bench times operating an estate already split into 1,361 states. Building and splitting that estate is setup, before the clock starts. What makes it hard:

  • Each state belongs to its own root, and roots read each other’s state, so they apply in order, in waves.
  • Each root planned or applied starts its own provider process, about 800 MB.
  • The worst case is a change all of them take: a bump to a shared tags module.
  • Plan notes and reports must fit the forge’s comment limit and stay readable.
Wall time of each scale run, by phase79 resources in 11 roots: 3 minutes, 1 minutes to reconcile, 1 to create, 1 to plan the change and 1 to apply it. 301 resources in 41 roots: 9 minutes, 2 minutes to reconcile, 2 to create, 1 to plan the change and 2 to apply it. 745 resources in 101 roots: 20 minutes, 5 minutes to reconcile, 6 to create, 3 to plan the change and 6 to apply it. 3,705 resources in 501 roots: 42 minutes, 10 minutes to reconcile, 14 to create, 7 to plan the change and 11 to apply it. 10,069 resources in 1,361 roots: 120 minutes, 27 minutes to reconcile, 41 to create, 20 to plan the change and 32 to apply it.0 min30609012079 resources, 11 roots3 minReconcile: 1 min (44 s)Create: 1 min (60 s)Plan: 1 min (30 s)Change: 1 min (55 s)301 resources, 41 roots9 minReconcile: 2 min (145 s)Create: 2 min (145 s)Plan: 1 min (88 s)Change: 2 min (148 s)745 resources, 101 roots20 minReconcile: 5 min (284 s)Create: 6 min (347 s)Plan: 3 min (167 s)Change: 6 min (382 s)3,705 resources, 501 roots42 minReconcile: 10 min (617 s)Create: 14 min (814 s)Plan: 7 min (429 s)Change: 11 min (638 s)10,069 resources, 1,361 roots120 minReconcile: 27 min (1593 s)Create: 41 min (2457 s)Plan: 20 min (1225 s)Change: 32 min (1945 s)
The largest run, 10,069 resources in 1,361 roots across 12 repos, took 120 minutes end to end: 27 minutes to reconcile, 41 to create, 20 to plan the change and 32 to apply it. The smallest, 79 resources, took 3.
ResourcesMinutesRunner minutesLargest noteLargest report
7911 roots, 2 repos3433 kB121 kB
30141 roots, 2 repos91198 kB475 kB
745101 roots, 2 repos2023228 kB1.2 MB
3,705501 roots, 5 repos4294398 kB2.3 MB
10,0691,361 roots, 12 repos120287398 kB5.2 MB

Each run used a build just after 0.4.1 on macOS arm64, 3 jobs at once. Over the largest run the machine's mean one-minute load was 16.11 on 18 CPUs. No plan note in the largest run was cut to fit the comment limit.

A run passes only when every phase succeeds and the state files hold every resource the estate declares. It runs on a local Forgejo against an AWS emulator.

One run of the scale benchSetup, not timed: terralith-gen writes one root module and the bench carves it into 1,361 roots in 12 repos. Timed: in the reconcile phase the control repo, whose terragucci.yml lists 12 repos, opens one pipeline pull request per repo. The create, plan and change phases run in the repos: the platform repo applies the platform root in wave 1 and the 272 roots that read its state in wave 2; 11 more repos hold 1,088 roots, 100 to a repo, that read no state. Both write to the state and reports buckets: a state file per root and a report per stage. Verify checks that the state files hold all 10,069 resources.setupnot timedterralith-gen writes one root modulecarved into 1,361 roots in 12 reposreconcilecreateplanchangecontrol repoterragucci.yml lists 12 reposone pipeline pull request per repoplatform repowave 1platform rootwave 2272 roots read it11 more repos1,088 roots,100 to a reporead no statestate and reports bucketsa state file per root, a report per stageverifyverifythe state files hold all 10,069 resources

Each timed phase starts at its first push or merge and ends when its last run does.

  1. Setup: the bench builds the estate and pushes each repo with no pipeline.
  2. Reconcile: reconcile --mode apply in the control repo opens a pipeline pull request in every repo it lists, and each is checked and planned.
  3. Create: the bench merges them, and each repo’s waves apply its platform root first, then the roots that read its state.
  4. Plan: a pull request in each repo changes modules/estate, which every root calls, so each repo gets one plan note covering all its roots.
  5. Change: the bench merges those, and the waves apply the new tags.
  6. Verify: the state files must hold every resource.
  • parallelism is 4 in each repo’s terragucci.yml: four roots at once, each with its own provider.
  • The runner takes 3 jobs at once, so repos run side by side only that far.
  • Each root commits .terraform.lock.hcl. Without lock files, init downloads the provider again each time: on the 301-resource estate a run took 24 minutes without them and 8 with them.
  • The emulator answers at once. A cloud account adds API latency and throttling, and IAM’s default quota of 1,000 roles is below the 1,496 this estate declares.

The bench’s own scripts build the estate. choudoufu’s terralith-gen writes a terralith at a chosen scale: one root module of AWS resources. A script then carves it into roots and spreads them over repos.

Root Holds Repo
Platform the network, ECS cluster and Route 53 zone platform
Service one ECS service, its task definition and its IAM role platform
DNS ten Route 53 records platform
Team one team’s IAM role and policies the other repos, 100 a repo
count or module teams two teams the other repos, 100 a repo

Service and DNS roots read the platform root’s state. Sharing its repo lets its waves order them.

The bench starts its own containers and calls no cloud. CONTRIBUTING.md says how to run it.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.