Choose the plan, state, or saved Form that contains the evidence your question needs.
rootform run detects input by content, not filename. Rootform reads local
files and never runs Terraform or OpenTofu, contacts providers, or refreshes
infrastructure.
Export a completed saved plan with terraform show -json plan.tfplan > plan.json.
OpenTofu users run the same command with tofu. A verified
--plan-file plan.tfplan can establish direct identity traversals that the
JSON export does not preserve. A plan may contain planned, refreshed, and
recorded stages, depending on what the plan contains. Rootform shows
Reported drift separately from Planned changes. See
Terraform and OpenTofu plans for production, verification, and
completeness.
When the working directory already has state, export it with
terraform show -json > state.json. State JSON contains instances and
sensitivity masks, but no configuration expressions or before and after plan
values. It cannot prove that no drift occurred. A raw terraform.tfstate file
is a different shape and is not accepted.
A working directory without state, such as a new example, exports only a
format version. Rootform refuses that file with status 3, says that it
records no state, and suggests the plan commands instead.
A saved Form is reusable input. The same run command can
open it without the plan or save a report. A saved single-input Form can
also be compared with a later input.
An input comparison orders the first input as Before and the --diff
input as After. A fact that cannot be settled on both sides stays
indeterminate; it
never counts as no change. A comparison Form reopens alone with
rootform run comparison.json; it cannot be a --diff operand.
rootform run analysis.json --no-serve -o report.mdThe file is a readable report of the saved Form. It does not rerun Terraform or OpenTofu or add evidence missing from that Form.
A configuration directory is not an analysis input: it is a project location.
--project selects its Dialects, and Policy Packs for check; it does not supply infrastructure
evidence. A binary saved plan alone is also not an input: export its JSON first,
then optionally pair the two files. Rootform refuses malformed JSON, plan event
streams from plan -json, and unrecognized input rather than inferring a
partial architecture.
To produce the export and pair its saved plan, continue with Terraform and OpenTofu plans. For a pull request with two planned revisions, go on to Review a pull request.