Skip to content

Choose the plan, state, or saved Form that contains the evidence your question needs. rootform run detects input by content, not filename. Rootform reads local files and never runs Terraform or OpenTofu, contacts providers, or refreshes infrastructure.

QuestionInputWhat it establishes
What would this operation create or change?Plan JSON, preferably paired with its saved planPlanned instances; available earlier stages, drift records, and comparisons
What does this plan show without its saved plan?Plan JSON aloneEvaluated values and dependencies, with unknown identity traversals left unresolved
What is recorded in state?State JSONOne Recorded architecture, without plan changes, refresh evidence, or configuration traversals
Can I reopen a prior result?Saved FormThe validated Form, including its original stage evidence, without reanalyzing plan or state JSON
Can I compare two points in time?Two accepted inputs with --diffAn architectural comparison; it is not a drift report
Can I stream an export?- on standard inputThe same content-based detection; at most one comparison operand may read the stream

Choose a plan for change evidence

Export a completed saved plan with terraform show -json plan.tfplan > plan.json. OpenTofu users run the same command with tofu. A verified --plan-file plan.tfplan can establish direct identity traversals that the JSON export does not preserve. A plan may contain planned, refreshed, and recorded stages, depending on what the plan contains. Rootform shows Reported drift separately from Planned changes. See Terraform and OpenTofu plans for production, verification, and completeness.

Choose state for a Recorded architecture

When the working directory already has state, export it with terraform show -json > state.json. State JSON contains instances and sensitivity masks, but no configuration expressions or before and after plan values. It cannot prove that no drift occurred. A raw terraform.tfstate file is a different shape and is not accepted.

A working directory without state, such as a new example, exports only a format version. Rootform refuses that file with status 3, says that it records no state, and suggests the plan commands instead.

Reuse or compare Forms

A saved Form is reusable input. The same run command can open it without the plan or save a report. A saved single-input Form can also be compared with a later input. An input comparison orders the first input as Before and the --diff input as After. A fact that cannot be settled on both sides stays indeterminate; it never counts as no change. A comparison Form reopens alone with rootform run comparison.json; it cannot be a --diff operand.

rootform run analysis.json --no-serve -o report.md
Shell

The file is a readable report of the saved Form. It does not rerun Terraform or OpenTofu or add evidence missing from that Form.

A configuration directory is not an analysis input: it is a project location. --project selects its Dialects, and Policy Packs for check; it does not supply infrastructure evidence. A binary saved plan alone is also not an input: export its JSON first, then optionally pair the two files. Rootform refuses malformed JSON, plan event streams from plan -json, and unrecognized input rather than inferring a partial architecture.

To produce the export and pair its saved plan, continue with Terraform and OpenTofu plans. For a pull request with two planned revisions, go on to Review a pull request.