All skills
github avatar

/terraform-azurerm-set-diff-analyzer

@a6f3cde official
by githubgithub/awesome-copilot40k stars
5,040

Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/terraform-azurerm-set-diff-analyzer

This session only. Nothing lands on disk.

referencesazurerm_set_attributes.md

≈992 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AzureRM Set-Type Attributes Reference

This document explains the overview and maintenance of azurerm_set_attributes.json.

Last Updated: January 28, 2026

Overview

azurerm_set_attributes.json is a definition file for attributes treated as Set-type in the AzureRM Provider. The analyze_plan.py script reads this JSON to identify "false-positive diffs" in Terraform plans.

What are Set-Type Attributes?

Terraform's Set type is a collection that does not guarantee order. Therefore, when adding or removing elements, unchanged elements may appear as "changed". This is called a "false-positive diff".

JSON File Structure

Basic Format

{
  "resources": {
    "azurerm_resource_type": {
      "attribute_name": "key_attribute"
    }
  }
}
  • key_attribute: The attribute that uniquely identifies Set elements (e.g., name, id)
  • null: When there is no key attribute (compare entire element)

Nested Format

When a Set attribute contains another Set attribute:

{
  "rewrite_rule_set": {
    "_key": "name",
    "rewrite_rule": {
      "_key": "name",
      "condition": "variable",
      "request_header_configuration": "header_name"
    }
  }
}
  • _key: The key attribute for that level's Set elements
  • Other keys: Definitions for nested Set attributes

Example: azurerm_application_gateway

"azurerm_application_gateway": {
  "backend_address_pool": "name",           // Simple Set (key is name)
  "rewrite_rule_set": {                     // Nested Set
    "_key": "name",
    "rewrite_rule": {
      "_key": "name",
      "condition": "variable"
    }
  }
}

Maintenance

Adding New Attributes

  1. Check Official Documentation

    • Search for the resource in Terraform Registry
    • Verify the attribute is listed as "Set of ..."
    • Some resources like azurerm_application_gateway have Set attributes noted explicitly
  2. Check Source Code (more reliable)

    • Search for the resource in AzureRM Provider GitHub
    • Confirm Type: pluginsdk.TypeSet in the schema definition
    • Identify attributes within the Set's Schema that can serve as _key
  3. Add to JSON

    "azurerm_new_resource": {
      "set_attribute": "key_attribute"
    }
  4. Test

    # Verify with an actual plan
    python3 scripts/analyze_plan.py your_plan.json

Identifying Key Attributes

Common Key Attribute Usage
name Named blocks (most common)
id Resource ID reference
location Geographic location
address Network address
host_name Hostname
null When no key exists (compare entire element)

Related Tools

analyze_plan.py

Analyzes Terraform plan JSON to identify false-positive diffs.

# Basic usage
terraform show -json plan.tfplan | python3 scripts/analyze_plan.py

# Read from file
python3 scripts/analyze_plan.py plan.json

# Use custom attribute file
python3 scripts/analyze_plan.py plan.json --attributes /path/to/custom.json

Supported Resources

Please refer to azurerm_set_attributes.json directly for currently supported resources:

# List resources
jq '.resources | keys' azurerm_set_attributes.json

Key resources:

  • azurerm_application_gateway - Backend pools, listeners, rules, etc.
  • azurerm_firewall_policy_rule_collection_group - Rule collections
  • azurerm_frontdoor - Backend pools, routing
  • azurerm_network_security_group - Security rules
  • azurerm_virtual_network_gateway - IP configuration, VPN client configuration

Notes

  • Attribute behavior may differ depending on Provider/API version
  • New resources and attributes need to be added as they become available
  • Defining all levels of deeply nested structures improves accuracy

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is a standard diagnostic utility for Terraform users. It consists of a standalone Python script and JSON configuration files used to analyze local Terraform plan data. It does not perform network operations, execute remote code, or require third-party dependencies.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    6/6 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at a6f3cde. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 8 months ago
  • Python
  • terraform
  • azurerm
  • azure
  • plan
  • diff
  • set-types
  • ci-cd

README badge

README badge for github/awesome-copilot/terraform-azurerm-set-diff-analyzer

Filters false-positive diffs in Terraform plans for AzureRM resources caused by Set-type attribute reordering. Use when terraform plan shows widespread changes to Application Gateway, Load Balancer, NSG, or Firewall but you only modified a single element. Includes a Python script to parse plan JSON and distinguish spurious diffs from actual resource changes.

Generated from the current SKILL.md.

Does this work with all Terraform providers or just AzureRM?
It targets AzureRM Provider specifically. The skill focuses on Set-type attributes common in Azure resources like Application Gateway, Load Balancer, and NSG, though the underlying issue affects other providers too.
What does the script output?
It analyzes terraform plan JSON to identify false-positive diffs caused by Set reordering versus actual resource changes, helping you filter spurious changes in review and CI/CD workflows.
What are the Python requirements?
Python 3.8 or later. The script uses only the standard library, so no additional packages need to be installed.
Can this be integrated into CI/CD pipelines?
Yes. The skill includes exit codes and output formats designed for CI/CD integration; see scripts/README.md for examples.

Generated from the current SKILL.md. These answers refresh after source changes.