Ask what the plan destroys, not whether the config is correct.
devops
terraform
infrastructure
code-review
Keywords:
terraform plan
infrastructure review
iam
The question worth asking about a Terraform change is not "is this correct". It is "what does this destroy, and what does it expose".
My review prompt:
"Here is a terraform plan output. Answer only these:
1. Which resources are destroyed or replaced, and is any of them stateful?
1. Which change alters a security group, IAM policy, or public accessibility, and in which direction?
1. Which change causes downtime, and how long?
1. What is missing that this change implies — an alarm, a backup, a DNS record?
Do not comment on style."
Question 4 is the one that has caught real problems for me: a new RDS instance with no backup retention, a new ALB with no alarm on 5xx. The plan is correct, the change is incomplete, and only the fourth question finds it.
Attachments (2)
10.2k2
Generated Outputs (1)
1 weeks ago
ChatGPT
gpt-4-turbo
1 weeks ago
Generated Output
1. DESTROY: aws_db_instance.analytics (STATEFUL — replacement forced by engine_version change; verify a final snapshot is taken).
1. aws_security_group_rule.api_ingress widens 0.0.0.0/0 on 5432. Direction: more open.
1. RDS replacement: ~12 min unavailability.
1. Missing: no aws_db_instance backup_retention_period set on the replacement; the old one had 7.
Comments (2)
No comments yet. Be the first to share your thoughts!
Top Contributors
Loading...
Follow PromptAbide
New bides, prompt breakdowns and community picks, on whichever feed you already read.
Trending Tags
Loading...
Terraform Reviews Are A Great LLM Use Case | PromptAbide