Open source · Cloud & Platform

Terraform Provider Schema Guard

Detect provider schema changes that can alter infrastructure plans.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Offline, read-only comparison of exported, normalized provider schemas against an exported configuration inventory. It never invokes Terraform/OpenTofu, loads a provider plugin, reads live state, plans, applies, provisions, or deletes anything. The exporter must produce complete evidence; this tool cannot verify completeness against a provider.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

git clone https://github.com/edilec/terraform-provider-schema-guard.git
cd terraform-provider-schema-guard
node bin/terraform-provider-schema-guard.mjs --root examples --input passing.json
node bin/terraform-provider-schema-guard.mjs --root examples --input failing.json
npm run check

Read the result

--root is the realpath-confined input directory. --input is a relative path within it. Optional --human writes one summary to stderr; JSON report only on stdout. No output file is written. Invalid usage/options: exit 2 with empty stdout. Unreadable/undecodable/unparseable/unsupported evidence: incomplete JSON and exit 2. Evaluated harmful changes: fail and exit 1. Fully evaluated compatible evidence: pass and exit 0. --help prints usage.

Where this check stops

At most 1,048,576 input/document UTF-8 bytes; 100 resources per side; 1,000 fields total per side; 500 configuration items; JSON depth 6 from root depth 0; 5,000 ms using an injectable library clock. Exact N is accepted, N+1 incomplete. CLI file read has a 5-second abort. Strict UTF-8 and duplicate-key rejection (including escaped spellings) prevent partial/ambiguous evidence. No network, live provider discovery, external execution, automatic remediation, or semantic equivalence inference.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.