WoluTools

Developer Tools

See what a Terraform plan will destroy or replace

Upload the output of terraform show -json. You get every create, update, delete and replace by resource name, with the destructive changes listed first.

or drop it here

JSON · Up to 100,000 resource changes
Free account needed for your 3 free jobs a day

No file at hand? See the prepared example

Standard toolIncluded · 3 free jobs a dayFree: 3 jobs a dayPro: up to 200 jobs a day · €12.99/month or €89.99/year
  • JSON
  • Up to 100,000 resource changes
Prepared result preview · fictional sample dataFictional Terraform Plan Action Inventory fixture
Source
1 prepared source file · 72 bytes
Measured interpretation
  • Resources: 1
  • Review required: 0

changes.csv · findings.csv · manifest.json

BringJSON
GetChange-action CSV, destructive/replacement findings and manifest
PrivacyEncrypted source · 24-hour result

One clear job, from source to download

  1. 1

    Add the source

    Supported formats and limits are visible before the upload.

  2. 2

    Confirm the settings

    Review the exact source, options, units and access before processing.

  3. 3

    Inspect and download

    Check the preview and warnings, then unlock the complete package.

Checking a Terraform plan for deletes and replacements

What you bring

You bring the JSON output of terraform show -json, run against a saved plan file. A binary .tfplan file or raw HCL is rejected. One job takes up to 100,000 resource changes. Only plans that declare a supported format_version are read, and an unknown version is refused instead of guessed at. Nothing is applied and no provider API is contacted. The tool reads only the resource changes already written in your plan.

What you get back

You get changes.csv, which lists every create, update, delete, replacement and no-op by full resource address. Module paths and count or for_each keys stay in the address, so two instances never merge into one row. You also get findings.csv, which lists deletions and replacements, because both destroy something that exists. A small manifest.json file records which file was read and a summary of the counts. Compare that summary with your plan before you share the result.

What stays with you

There are no settings. The tool only reports facts that are present in the plan. An action list that holds both delete and create is reported as a replacement, not an update. It does not estimate cost, check for known vulnerabilities or give a compliance verdict, and it does not read live state. Whether a replacement is safe to apply stays your decision, and the decision of whoever reviews infrastructure changes on your team.

Questions before you run it

Which terraform command produces the JSON this tool reads?

Run terraform show -json against a saved plan file and upload that output. A binary .tfplan file or raw HCL is rejected, because only the JSON representation carries the classified action list.

Does it read my cloud credentials or live state?

No. Nothing is applied and no provider API is contacted. Every action comes from the resource_changes entries already present in the plan JSON you uploaded.

How are replacements told apart from ordinary updates?

An action list containing both delete and create is reported as a replacement, not an update. Replacements land in findings.csv alongside plain deletions, since both destroy something that exists.

What happens to modules, count and for_each instances?

Each instance keeps its full resource address, including the module path and the index key. Two instances of the same resource never collapse into a single row.

How large a plan can I upload, and what about unfamiliar plan formats?

Up to 100,000 resource changes per job. Only plans that declare a supported format_version are parsed; an unknown version is refused rather than interpreted on a guess.