🏗️ Terraform Analyzer — Interactive Demo

Every plan is a recipe.
Is yours safe to serve?

Twelve analyzers. Blast radius, security, cost, drift, policy, and more — running on every infrastructure PR before it merges.

Runs via the same prkitchen CLI — pipe a plan in CI or locally: terraform show -json tfplan | prkitchen analyze.

Waiting
terraform plan output risky
prkitchen — terraform analyzer Risky
$ awaiting plan...
🔍 All 12 Analyzers

Twelve analyzers. One PR comment. Zero surprises.

Every check runs in parallel on every infrastructure PR — no plugins, no extra config, no CI pipelines to maintain.

📋

Plan Summary

Creates, updates, deletes, replaces — laid bare. Overall risk level surfaced before a reviewer opens the PR.

💥

Blast Radius

Scores 0–100 how much is actually at stake. Maps the full blast zone: networking, compute, storage, IAM.

🛡️

Destructive Guard

Blocks RDS replacements, VPC deletions, and data-loss operations. Checks backup posture before any deletion.

🔒

Security Analysis

IAM wildcards, open ports, unencrypted buckets, hardcoded secrets — caught at PR time, not after an incident.

📜

Policy Compliance

Mandatory tags, approved regions, encryption requirements. Every violation surfaces with its policy ID and a fix.

💸

Tags & Cost

Monthly cost before, after, and delta per resource. Tag compliance score. No more PRs that silently double your bill.

🔄

Drift Analysis

Resources that drifted from declared state are surfaced before you apply more changes on top of them.

🏗️

Structure & Refactoring

countfor_each migrations, module extraction, variable hygiene — with suggested code attached.

🕸️

Dependency Graph

Maps the full dependency tree. High-impact nodes — resources many others depend on — are flagged for extra review.

📤

Output Analysis

Flags broken output references and sensitive value exposure before downstream terraform_remote_state consumers break.

🎲

Non-Determinism

Catches timestamp(), uuid(), and other patterns that cause perpetual plan noise on every apply.

📦

Module Versions

Verifies all module sources pin an explicit version. Floating references are flagged before a registry update breaks your plan.

Reserve Your Table 🍽️ See Full Analyzer Docs →