run compiles one plan or state export into a Form, opens a saved Form, or
compares two accepted inputs. It detects their kind from content. A plan or
state export is analyzed with the active Dialects; a saved Form is
validated and loaded without reinterpretation.
With --diff <input>, each operand is a plan, a state, or a saved
single-input Form; a comparison Form reopens alone and is never a --diff
operand. At most one operand may read standard input. A configuration
directory and a binary saved plan are not analysis inputs. --project <dir>
selects project Dialect content; it does not read that directory as
infrastructure evidence. See Choose an input.
rootform run <input> [--diff <input>] [options]Analyze one plan, then save its Form:
rootform run plan.json --plan-file plan.tfplan --require-enrichment --no-serve -o analysis.jsonThe summary goes to standard output, and Wrote analysis.json to standard
error. The status is 0; a saved plan that fails verification exits 3
because of --require-enrichment.
The quickstart reads the same summary
step by step.
Compare two plan exports and save a Markdown report:
rootform run base/plan.json --plan-file base/plan.tfplan \ --diff head/plan.json --diff-plan-file head/plan.tfplan \ --no-serve -o comparison.mdThe comparison summary goes to standard output. comparison.md contains a
Markdown review with bounded lists; --details includes every entry. See
Review with Markdown.
Differences are not failures: the status is 0.
--stage selects the reported stage of one input. With
--diff, use --before-stage and --after-stage; a missing or ambiguous
stage is refused with available choices. A plan defaults to planned;
a state defaults to recorded. The saved Form keeps every stage its input
supports, whatever stage the summary reports; rootform check chooses the
stage it evaluates on its own.
By default, run starts a loopback-only server, opens a browser, and
stays in the foreground until interrupted. --no-browser leaves browser
launch to you. --port 0 selects an available port. --no-serve
writes requested outputs and exits. The server analyzes once; it does not
watch files or replan. See Explore a Form.
See Outputs and exit status for the complete file-format, stream, collision, and write-failure contract.
Embedded Dialects work without a lock. --locked requires a valid
rootform.lock for the selected project. --dialect selects local
Dialect sources for this analysis; an override cannot be combined with
--locked. run does not select or evaluate Policies. Use
rootform check for a separate Policy gate.
--plan-file verifies and enriches the first plan; --diff-plan-file
does the same for the second. --require-enrichment refuses a failed
pairing. --producer, --provider-map, and
--plan-complete=attested record operator claims rather than
facts established by the plan. See plan inputs.
Status 0 means the Form was produced or opened; 2 means the command was
used incorrectly; 3 means an input was refused, rootform.lock is invalid,
or a requested stage is unavailable; 4 means an input or output file, or the
explorer, failed. Architectural differences and reported drift do not by
themselves make the command fail. Read the exact
output contract.