GET STARTED

Install Terradune

Install locally with Go and use the Terraform or OpenTofu CLI on your machine. Go is the sole supported installation method.

1. Install Go

Terradune requires Go 1.27.1 or newer. Choose your operating system and architecture at go.dev/dl.

go version

Verify the reported version is at least 1.27.1. Install Terraform or OpenTofu separately and make sure its command is on PATH.

2. Install Terradune

go install github.com/albatroxxx/terradune@latest

Use @v1.0.6 instead of @latest to pin this release. Add Go's executable directory to PATH. For the current macOS/Linux terminal:

go_bin="$(go env GOBIN)"
export PATH="${go_bin:-$(go env GOPATH)/bin}:$PATH"
terradune -version

Put the same setup in your shell profile, such as ~/.zshrc or ~/.bashrc, for future terminals. For the current Windows PowerShell session:

$goBin = go env GOBIN
if (-not $goBin) { $goBin = Join-Path (go env GOPATH) "bin" }
$env:Path = "$goBin;$env:Path"
terradune -version

For future Windows sessions, add that directory to your user Path in Environment Variables. A custom GOBIN takes precedence over the default GOPATH/bin directory.

AWS credentials

Terradune uses your CLI's provider authentication, including environment credentials, AWS profiles, SSO, and credential helpers. Log in using your existing AWS workflow before planning. Keep credentials out of committed configuration and screenshots.

3. Review a plan

terraform -chdir=./infra init
terradune ./infra

Replace ./infra with your workspace. With OpenTofu, use tofu -chdir=./infra init. Terradune uses Terraform when available and otherwise falls back to OpenTofu.

Open localhost:8383, or the URL printed in your terminal. Stop with Ctrl+C. If the port is occupied, use terradune -port 8484 ./infra.

Resource Map is the default view. Single-click pins a path; double-click or Focus path narrows dependencies while retaining VPC and subnet sections. Filled teal circles mark direct connections; hollow blue circles mark indirect associations. Plan lists each managed resource once per workspace. Resource types and counts follow action, search, workspace and changes-only filters. Open a resource for What changes, with explicit Before and After values. Graph shows dependencies, with arrows pointing from a dependent to its prerequisite.

terradune -var-file prod.tfvars -var region=eu-west-2 ./infra

Update or remove

Stop Terradune, run the install command again, and check terradune -version. To remove it, delete terradune or terradune.exe from your Go executable directory. Keep your Terraform workspaces and state files intact.

Compatibility

Supported in v1Not yet first-class
Managed resource changes, including unfamiliar AWS typesData-source inventory and read actions
Create, update, replace, destroy, unchangedImports, moves, forgotten resources, and output changes
Module addresses, count, for_each, multiple working directoriesDeferred plans and complete provider-alias account/region modeling
Unknown values and Terraform sensitivity masksAutomatic discovery of unmarked secrets

CI tests Terraform 1.16.2 and OpenTofu 1.12.6 on Linux, macOS, and Windows. Fixtures also cover Terraform 1.14.4. Other versions may work; your CLI and provider constraints determine which configurations can be planned.

Keep it local

Terradune never runs apply. Planning can still contact AWS, data sources, remote backends, and external programs referenced by your configuration. Only run trusted projects.

The server defaults to 127.0.0.1 and has no authentication or TLS. Keep it local. Sensitive values are masked using Terraform's metadata, but unmarked secrets and diagnostics still require care.

See the security policy and release process.