πŸ—οΈ
✦
Tonight's Special EntrΓ©e

Terraform, Prepared & Refined

Served fresh on every infrastructure PR

Infrastructure changes carry more risk than application code β€” a bad merge can take down production, inflate your cloud bill, or open a security hole that takes weeks to find. PRKitchen runs twelve analyzers across every Terraform plan before your PR reaches a reviewer.

πŸ—οΈ Try the Interactive Demo β†’
The PRKitchen approach to infrastructure
Prepare & Refine β€” for Terraform
01
Prepare
Plan before you apply.
  • Β·Run terraform plan and capture the JSON output.
  • Β·Know what resources you're creating, changing, or destroying.
  • Β·Confirm the change is linked to a ticket β€” intent on record.
  • Β·Keep the scope to one logical infrastructure change.
02
Refine
Twelve chefs check the dish.
  • Β·Blast radius scored β€” how much is actually at stake.
  • Β·Security findings flagged before they reach production.
  • Β·Policy violations caught with a suggested fix attached.
  • Β·Destructive changes intercepted β€” prod resources, replace cause, backup posture.
  • Β·Drift detected. Structure improvements surfaced.
03
Open
A PR your infra team can trust.
  • Β·Auto-generated PR comment with the full analysis attached.
  • Β·Reviewers see findings, not raw JSON.
  • Β·Merge with confidence β€” the kitchen already checked.
  • Β·Audit trail on every infrastructure change, automatically.
πŸ“œ

The Twelve-Course Tasting Menu

Every analyzer included. Every infrastructure PR.

β€”β€”Served on every Terraform PRβ€”β€”
πŸ“‹
First Course

Plan Summary

Included βœ“

Every resource change laid bare β€” creates, updates, deletes, replaces. PRKitchen reads the full plan and surfaces the overall risk level before a single reviewer opens the PR. Risky changes are flagged by name, not buried in a wall of JSON.

🍴If you can't summarise what your plan does in one glance, it's not ready to merge.
πŸ’₯
Second Course

Blast Radius

Included βœ“

How many resources does this change touch β€” really? Blast radius scoring maps the full blast zone: networking, compute, storage, IAM. A score out of 100 tells you how much is at stake before the apply button gets anywhere near production.

🍴Small plans can have large blasts. Better to know now than after.
πŸ”
Third Course

Security Analysis

Included βœ“

Three vectors, one pass: IAM exposure, network posture, and secrets hygiene. Every finding is labelled critical, high, medium, or low with a specific recommendation attached. Open ports, overpermissioned roles, and hardcoded secrets don't make it to the table.

🍴Security findings in a Terraform plan are the cheapest kind to fix. Catch them here.
πŸ“œ
Fourth Course

Policy Compliance

Included βœ“

Your organisation has rules. PRKitchen enforces them automatically β€” mandatory tags, approved regions, required encryption, naming conventions. Every violation surfaces with its policy ID and a suggested fix, not just a red flag.

🍴Manual policy checklists get skipped under deadline. Automated ones don't.
πŸ›‘οΈ
Fifth Course

Destructive Guard

Included βœ“

Deletions and replacements that would cause data loss or downtime are intercepted before the PR opens. Production-tier resources (anything named prod, prd, live, or main) are automatically escalated to critical severity. Replace operations are explained by the exact attribute forcing the change β€” not just "this will be replaced." Destroy-before-create replacements are flagged separately from create_before_destroy ones. Backup posture is checked before any deletion: RDS retention period, DynamoDB point-in-time recovery, and S3 versioning are verified so you know whether a rollback is even possible.

🍴terraform destroy should never be a surprise. Neither should destroy-before-create on a prod database.
πŸ’°
Sixth Course

Tags & Cost

Included βœ“

Tag compliance score, monthly cost before, monthly cost after, delta per resource. No more infra PRs that silently double your AWS bill. Missing required tags are called out by resource address so nothing slips through untagged.

🍴Cost surprises are optional. This makes them avoidable.
πŸ”„
Seventh Course

Drift Analysis

Included βœ“

Resources that have drifted from their declared state are surfaced before you apply more changes on top of them. Stale and legacy resources that should have been removed long ago are flagged with a remediation strategy.

🍴Drifted infra and new changes are a bad combination. Know before you apply.
πŸ—οΈ
Eighth Course

Structure & Refactoring

Included βœ“

HCL quality analysis: count-to-for_each migrations, module extraction opportunities, variable hygiene, and dependency simplification. Each suggestion comes with the proposed code and step-by-step migration instructions β€” not just a comment.

🍴Technical debt in Terraform compounds faster than in application code. Catch it in review.
πŸ•ΈοΈ
Ninth Course

Dependency Graph

Included βœ“

Maps the full dependency tree between resources so reviewers understand blast propagation paths. Resources that many others depend on are flagged as high-impact nodes β€” a change to them can cascade across the entire plan.

🍴Knowing what depends on what is the difference between a safe change and a silent cascade.
πŸ“€
Tenth Course

Output Analysis

Included βœ“

Validates that outputs are correctly typed, not accidentally exposing sensitive values, and consistent with what downstream modules expect. Outputs that reference destroyed resources are flagged as broken before the apply runs.

🍴Broken outputs are silent until a downstream consumer fails. Catch them here.
🎲
Eleventh Course

Nondeterminism Detection

Included βœ“

Detects random_* resources and nondeterministic function calls β€” timestamp(), uuid(), bcrypt() β€” that cause perpetual plan noise unless protected by lifecycle ignore_changes. Each finding includes the remediation pattern.

🍴Perpetual diffs are a sign of nondeterminism, not real change. Silence the noise.
πŸ“¦
Twelfth Course

Module Version Check

Included βœ“

Verifies that all module sources pin an explicit version constraint. Floating references (no version, or using "latest") are flagged as unpinned β€” a future registry change could silently alter behaviour on the next plan.

🍴Unpinned modules are a reproducibility risk. Pin them before they bite you.
πŸ—οΈ

Infrastructure PRs Deserve a Kitchen Too

Twelve analyzers. One PR comment. Full audit trail. PRKitchen makes infrastructure review as rigorous as application review.

Start free with 1 repo. No credit card required.