terraform-compliance review
A focused, readable way to validate Terraform plans and state before deployment.
Reviewed by iTechGuides Editors · Editorial team · Updated Oct 2026
terraform-compliance is an open-source command-line test framework for developers, infrastructure teams, and security teams that need automated compliance checks before applying Terraform changes. It uses BDD-style feature files to express readable policy scenarios, then validates Terraform plan or state output against those scenarios. Provider-agnostic checks allow the same testing approach across Terraform providers, while negative testing helps verify that prohibited infrastructure configurations are rejected.
The tool fits workflows that already use Git-based development and continuous integration. Feature files can come from local directories or Git repositories, and the published integrations include GitHub Actions, CircleCI, and Git hooks. Installation is available through pip or Docker, giving teams several ways to add validation to existing development and CI/CD processes. Its pre-deployment focus makes it suitable for catching compliance issues before infrastructure changes are applied, rather than managing controls after deployment.
terraform-compliance is free to use and open source, with no paid tier structure described. Its main strength is a narrow, clear scope: readable policy testing for Terraform plan and state output. That focus is useful for teams seeking policy-as-code checks without tying scenarios to a specific provider. It is less suitable for organizations that need one policy tool across multiple infrastructure-as-code formats, runtime enforcement, or broader admission and operational controls. Choose it when Terraform validation and BDD-style scenarios are the priority; consider a broader platform when policy coverage must extend beyond Terraform or continue into runtime environments.
terraform-compliance pros and cons
- Where it wins
- Readable BDD-style feature files for compliance scenarios
- Validates both Terraform plan and state output
- Works with CI/CD, Git hooks, pip, and Docker
- Where it doesn't
- Focused on Terraform rather than multiple IaC formats
- Provides pre-deployment validation, not runtime enforcement
- Requires policy checks to be expressed as feature files
terraform-compliance fact sheet, pricing and score →
Advertiser disclosure: iTechGuides is reader-supported. We may earn a commission when you click some links. How we rank.
Last updated · How we research and update