Skip to content

Tips

llms.txtlists every page for an agent

Each tip shows in the plan report and its pull request note, and in the terragucci reconcile dry run; tips: false turns them off.

They only advise. None fails a run or changes a gate, and no digest includes one.

The plan note on a pull request that lets dev search's AWS provider float, with its line counting the tips on how the roots are set upThe plan note on a pull request that lets dev search's AWS provider float, with its line counting the tips on how the roots are set up
The Tips section of the HTML report, from its heading through its last tip: terragucci-floating-range for envs/dev/search among them, each tip linked to its rule's pageThe Tips section of the HTML report, from its heading through its last tip: terragucci-floating-range for envs/dev/search among them, each tip linked to its rule's page

Code tips read the HCL itself. Those and the shared-module tip need npm i -D @cdktn/hcl2json; without it the job log says they were left out.

Rule The tip
TF002 a provider with no version in required_providers
TF003 no required_version
TF004 a registry module with no version
TF005 a git module with no fixed ?ref=
TF038 an oci:// module with no tag, or the latest tag
TF039 a registry module with a version range
TF040 no committed .terraform.lock.hcl
TF041 a Terragrunt dependency with mock_outputs whose allowed commands include apply or are not set
TF042 a Terragrunt dependency that sets skip_outputs with mock_outputs, so every run reads the mocks
TF043 a Terragrunt terraform.source with no version (a git ref, a tfr version or an oci tag)
TF044 a Terragrunt config that keeps its state in a local backend

Ten or more roots include a local module. Publish it with tf-publish and pin it, so tf-rollout moves only the pinned roots, in waves.

A module call is pinned to a range such as ~> 1.4, which a rollout cannot move. Pin one version.

It also covers a provider range in required_providers, which tf-rollout --provider cannot cross. When TF038 or TF039 names the call, only that tip is given.

A project has more than five roots and no waves.canary.

gate is never and a plan destroys or replaces something. Use gate: on-destructive.

A hundred or more roots are planned on every change. Publish and pin shared modules.

Plan tips read a root’s plan and show only in the plan report and its note.

A plan destroys one resource and creates another of the same type and provider, both in the root module and neither with a count or for_each key, and every value the create knows before apply equals the destroyed resource’s: the block was renamed. Adding a moved block makes the plan move it instead. terragucci respond tips --report <dir> --branch <branch> --mode apply opens a pull request into the branch that adds it (Responses).

Values known only after apply, and sensitive ones, are not compared. No tip is given when a destroy matches more than one create, or a create more than one destroy.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.