Skip to content

Standards

llms.txtlists every page for an agent

For a security review or a platform evaluation, each row below names a standard terragucci follows in its code today and links the page that shows it in use. Most of those pages name the smoke claims that prove it.

Page Answers
tacos.guru the 24 criteria and 5 gates of an independent Terraform platform evaluation, one by one
Access and identity SSO and RBAC: who decides each action, with no accounts of terragucci’s own
Standard terragucci uses it for Shown in
OpenTofu and Terraform CLI every plan and apply runs the binary you pin, against the state backend you already have; its plan JSON feeds policy and the report Choose your binary
Release checksums (SHA256SUMS) a pinned binary the image lacks is installed in the job only when its checksum matches its release’s Choose your binary
OpenID Connect federation each job trades the forge’s OIDC token for a short-lived role: AWS STS AssumeRoleWithWebIdentity, GCP workload identity federation, Azure federated credentials Credentials
OPA and Rego policies over each plan with conftest or OPA, including HCP Terraform’s policy-set input and policies.hcl Policy
OpenTelemetry (OTLP) one trace per run and its metrics, sent as OTLP/JSON over HTTP to the endpoint in the standard OTEL_EXPORTER_OTLP_* variables Send traces and metrics
DORA metrics deployment frequency, lead time, change failure rate and time to restore, computed from the audit trail Delivery metrics
Model Context Protocol terragucci mcp, a read-only MCP server on stdio over the estate, reports, state versions and audit trail Read the estate over MCP
SSH signatures under approval: sealed, an approval is an ssh-keygen -Y sign signature checked against a file in ssh’s allowed_signers format Set up the signers file
RFC 8785 (JSON Canonicalization Scheme) a plan digest, jcs1-sha256:, is SHA-256 over the canonical JSON of the plan’s change set, so key order never changes what an approval binds Approval binding
Terraform module registry protocol each module release is written as the protocol’s static files to your bucket, so roots pin registry sources Serve a module registry
OCI artifacts modules publish as OCI packages that OpenTofu roots pin Publish your modules
Conventional Commits and SemVer commit types decide each module’s next version Publish your modules
SLSA provenance and in-toto with modules.attest, each release carries SLSA v1 provenance in an in-toto statement, signed with cosign Attest each release
SPDX each attested release carries an SPDX 2.3 SBOM of its providers and modules Attest each release
JSON Schema the report, its indexes, the estate, the audit trail and DORA files ship schemas (draft 2020-12) a reader can validate against Report JSON schema
HMAC-SHA256 request signing webhook events are signed over their body; the chat relay checks Slack’s signing secret and the Teams outgoing webhook’s HMAC Webhook event schema, Approve from Slack and Teams
Signed object URLs reports open through S3 presigned links, GCS V4 signed URLs or Azure user delegation SAS, with no public bucket Keep reports in a bucket

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.