Docs › Agent
Infrastructure as code
How the agent works on Terraform, OpenTofu, Pulumi, Kubernetes, Helm and Docker without changing anything real you did not approve.
Infrastructure code describes things that exist outside your repository: cloud accounts, clusters, databases other people use. Nothing in the editor can undo an apply, so the agent works on it differently from ordinary code.
Plan before apply
An apply is refused until a plan has succeeded in the same run, so what you approve is something you could read. The approval for an apply then carries the plan itself: how many resources it creates, changes and destroys, and every resource it destroys or replaces by name. It also says where the change lands, the kubectl context and namespace or the Terraform workspace, and flags one that looks like production.
Two shapes are called out on the approval. A plan that destroys more than it adds or changes usually means the state, workspace or directory is not the one you think. An apply that is not the saved plan can apply something different from what you were shown.
A plan that was made and not applied appears under Needs you on the run card, with the command that applies exactly that plan.
Checks it runs
Before a run that changed infrastructure says it is finished, AstraCode runs the checks for what changed, with whichever tools you have installed:
| What changed | Checks |
|---|---|
| Terraform or OpenTofu | `fmt -check`, `validate` in a throwaway copy so your folder and lock file are untouched, `tflint`, and trivy, checkov or tfsec at high severity. A module is checked through the root that calls it. |
| Helm chart | `helm lint` |
| Kubernetes manifests | `kubeconform`, offline |
| Dockerfile | `hadolint` |
A check that fails only on files the run did not change was failing before it, and is not handed to the agent to fix.
What it is told not to do
- Change a resource the task did not ask about. A problem that was there before, such as an open security group or a public bucket, is listed under You need to do for you to decide on.
- Edit state by hand. It uses
movedandimportblocks, which go through a plan like everything else. - Destroy something to start fresh, or loosen a provider version to make validate pass.
- Leave a secret it finds in the code unmentioned.
The infrastructure skill
AstraCode ships a skill with the workflow and the conventions for each of these tools. It is attached automatically when the agent starts working in a .tf file, a Dockerfile, a Kubernetes manifest or a Helm chart, even when your message names none of them.
All documentation
Get started
Agent
- Agent overview
- Approvals and permissions
- Plan mode
- What the agent can do
- Running commands
- Browser tools
- Checkpoints and undo
- Infrastructure as code
- Running several agents at once