All skills
github avatar

/terraform-azurerm-set-diff-analyzer

@a6f3cde official
by githubgithub/awesome-copilot40k stars
5,040

Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/terraform-azurerm-set-diff-analyzer

This session only. Nothing lands on disk.

SKILL.md

≈111 tokens always: the name and description. ≈426 when used: this file. ≈3.6k more on demand in 3 files.

Terraform AzureRM Set Diff Analyzer

A skill to identify "false-positive diffs" in Terraform plans caused by AzureRM Provider's Set-type attributes and distinguish them from actual changes.

When to Use

  • terraform plan shows many changes, but you only added/removed a single element
  • Application Gateway, Load Balancer, NSG, etc. show "all elements changed"
  • You want to automatically filter false-positive diffs in CI/CD

Background

Terraform's Set type compares by position rather than by key, so when adding or removing elements, all elements appear as "changed". This is a general Terraform issue, but it's particularly noticeable with AzureRM resources that heavily use Set-type attributes like Application Gateway, Load Balancer, and NSG.

These "false-positive diffs" don't actually affect the resources, but they make reviewing terraform plan output difficult.

Prerequisites

  • Python 3.8+

If Python is unavailable, install via your package manager (e.g., apt install python3, brew install python3) or from python.org.

Basic Usage

# 1. Generate plan JSON output
terraform plan -out=plan.tfplan
terraform show -json plan.tfplan > plan.json

# 2. Analyze
python scripts/analyze_plan.py plan.json

Troubleshooting

  • python: command not found: Use python3 instead, or install Python
  • ModuleNotFoundError: Script uses only standard library; ensure Python 3.8+

Detailed Documentation

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a standard diagnostic utility for Terraform users. It consists of a standalone Python script and JSON configuration files used to analyze local Terraform plan data. It does not perform network operations, execute remote code, or require third-party dependencies.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at a6f3cde. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 8 months ago
  • Python
  • terraform
  • azurerm
  • azure
  • plan
  • diff
  • set-types
  • ci-cd

README badge

README badge for github/awesome-copilot/terraform-azurerm-set-diff-analyzer

Filters false-positive diffs in Terraform plans for AzureRM resources caused by Set-type attribute reordering. Use when terraform plan shows widespread changes to Application Gateway, Load Balancer, NSG, or Firewall but you only modified a single element. Includes a Python script to parse plan JSON and distinguish spurious diffs from actual resource changes.

Generated from the current SKILL.md.

Does this work with all Terraform providers or just AzureRM?
It targets AzureRM Provider specifically. The skill focuses on Set-type attributes common in Azure resources like Application Gateway, Load Balancer, and NSG, though the underlying issue affects other providers too.
What does the script output?
It analyzes terraform plan JSON to identify false-positive diffs caused by Set reordering versus actual resource changes, helping you filter spurious changes in review and CI/CD workflows.
What are the Python requirements?
Python 3.8 or later. The script uses only the standard library, so no additional packages need to be installed.
Can this be integrated into CI/CD pipelines?
Yes. The skill includes exit codes and output formats designed for CI/CD integration; see scripts/README.md for examples.

Generated from the current SKILL.md. These answers refresh after source changes.