Rootform analyzes local inputs without telemetry, cloud account access,
provider execution, or implicit package acquisition. It reads the plan JSON,
saved plan, or state JSON that Terraform or OpenTofu already produced; it never
runs either tool. Network access belongs to explicit preparation or
publication, plus the loopback server used by run.
--locked requires and preserves an existing rootform.lock; it does not
disable network acquisition by init. --offline prevents acquisition by
install, add, update, init, and vendor. An offline OCI tag cannot be
resolved; an already installed digest reference can be used. Normal analysis
fails when selected external content is unavailable. See
Locks and vendored content for selection and
Registry compatibility for the
tested transport boundary.
This matrix covers Rootform, not every tool in a workflow. Docker may pull an image before starting a container. Git checkout, Terraform/OpenTofu module or provider preparation, planning, and CI services have their own network and credential behavior. Rootform does not contact a cloud provider to fill an evidence gap.
A Form never copies attribute values, sensitive values, raw HCL,
saved plans, plan JSON, state, local paths, or Explorer state. It still records
resource and instance addresses, including count and for_each keys,
resource types, module paths, provider identities, planned actions,
relationships, closure results, diagnostics, and the Terraform or OpenTofu
version that the input reports. An external endpoint's identity is recorded
only when its Dialect allows that disclosure. Comparisons, Markdown and SARIF
reports, and HTML exports expose the same kind of information. Omitting raw
values does not anonymize the result.
An HTML export embeds the Explorer and a display copy of the Form
in one file. Opening it makes no network request. Anyone who receives the file
can read the names and topology in that copy; keep the .json Form when
you need the complete reusable result.
Review saved Forms, HTML exports, reports, and standard-error diagnostics before sharing them. Apply the same audience and retention rules as other infrastructure metadata. The plan guide explains the input risk, and Forms and stages describes what a saved Form retains.
A digest establishes which package bytes were selected and whether those bytes changed. It does not establish that a Dialect interprets a provider correctly or that a Policy Pack fits a project's requirements. A wrong Rule can produce the same wrong architecture deterministically. A policy result covers only matched targets, its assertion, and the evidence available to it.
Review external source, coverage, and assumptions before recording exact identities in a lock. Dialect and Policy Pack artifacts are bounded Rootform language data, not provider binaries or package-supplied shell code. Provenance shows why a claim was made; it does not verify deployed health or reachability.
Reduce a failure to synthetic configuration and a plan made from it. Record the Rootform version, command, exit status, and sanitized diagnostic while preserving the relevant reference or module shape. Never include credentials, real plans, state, or customer names in a public report.
Use Troubleshooting for operational symptoms, Limitations for product boundaries, and the security policy to report vulnerabilities privately.