Docs › Agent

Infrastructure as code

How the agent works on Terraform, OpenTofu, Pulumi, Kubernetes, Helm and Docker without changing anything real you did not approve.

Infrastructure code describes things that exist outside your repository: cloud accounts, clusters, databases other people use. Nothing in the editor can undo an apply, so the agent works on it differently from ordinary code.

Plan before apply

An apply is refused until a plan has succeeded in the same run, so what you approve is something you could read. The approval for an apply then carries the plan itself: how many resources it creates, changes and destroys, and every resource it destroys or replaces by name. It also says where the change lands, the kubectl context and namespace or the Terraform workspace, and flags one that looks like production.

Two shapes are called out on the approval. A plan that destroys more than it adds or changes usually means the state, workspace or directory is not the one you think. An apply that is not the saved plan can apply something different from what you were shown.

A plan that was made and not applied appears under Needs you on the run card, with the command that applies exactly that plan.

Checks it runs

Before a run that changed infrastructure says it is finished, AstraCode runs the checks for what changed, with whichever tools you have installed:

What changedChecks
Terraform or OpenTofu`fmt -check`, `validate` in a throwaway copy so your folder and lock file are untouched, `tflint`, and trivy, checkov or tfsec at high severity. A module is checked through the root that calls it.
Helm chart`helm lint`
Kubernetes manifests`kubeconform`, offline
Dockerfile`hadolint`

A check that fails only on files the run did not change was failing before it, and is not handed to the agent to fix.

What it is told not to do

The infrastructure skill

AstraCode ships a skill with the workflow and the conventions for each of these tools. It is attached automatically when the agent starts working in a .tf file, a Dockerfile, a Kubernetes manifest or a Helm chart, even when your message names none of them.

All documentation

Get started

Agent

Context

Workspaces

Connectors

Extending AstraCode

CLI

Reference