GET STARTED
Install Terradune
Install locally with Go and use the Terraform or OpenTofu CLI on your machine. Go is the sole supported installation method.
1. Install Go
Terradune requires Go 1.27.1 or newer. Choose your operating system and architecture at go.dev/dl.
- macOS: open the downloaded package installer and follow its prompts.
- Windows: run the MSI installer, then reopen PowerShell.
- Linux: follow the official installation steps to install into a fresh
/usr/local/godirectory and add/usr/local/go/binto PATH.
go versionVerify the reported version is at least 1.27.1. Install Terraform or OpenTofu separately and make sure its command is on PATH.
2. Install Terradune
go install github.com/albatroxxx/terradune@latestUse @v1.0.6 instead of @latest to pin this release. Add Go's executable directory to PATH. For the current macOS/Linux terminal:
go_bin="$(go env GOBIN)"
export PATH="${go_bin:-$(go env GOPATH)/bin}:$PATH"
terradune -versionPut the same setup in your shell profile, such as ~/.zshrc or ~/.bashrc, for future terminals. For the current Windows PowerShell session:
$goBin = go env GOBIN
if (-not $goBin) { $goBin = Join-Path (go env GOPATH) "bin" }
$env:Path = "$goBin;$env:Path"
terradune -versionFor future Windows sessions, add that directory to your user Path in Environment Variables. A custom GOBIN takes precedence over the default GOPATH/bin directory.
AWS credentials
Terradune uses your CLI's provider authentication, including environment credentials, AWS profiles, SSO, and credential helpers. Log in using your existing AWS workflow before planning. Keep credentials out of committed configuration and screenshots.
3. Review a plan
terraform -chdir=./infra init
terradune ./infraReplace ./infra with your workspace. With OpenTofu, use tofu -chdir=./infra init. Terradune uses Terraform when available and otherwise falls back to OpenTofu.
Open localhost:8383, or the URL printed in your terminal. Stop with Ctrl+C. If the port is occupied, use terradune -port 8484 ./infra.
Resource Map is the default view. Single-click pins a path; double-click or Focus path narrows dependencies while retaining VPC and subnet sections. Filled teal circles mark direct connections; hollow blue circles mark indirect associations. Plan lists each managed resource once per workspace. Resource types and counts follow action, search, workspace and changes-only filters. Open a resource for What changes, with explicit Before and After values. Graph shows dependencies, with arrows pointing from a dependent to its prerequisite.
terradune -var-file prod.tfvars -var region=eu-west-2 ./infraUpdate or remove
Stop Terradune, run the install command again, and check terradune -version. To remove it, delete terradune or terradune.exe from your Go executable directory. Keep your Terraform workspaces and state files intact.
Compatibility
| Supported in v1 | Not yet first-class |
|---|---|
| Managed resource changes, including unfamiliar AWS types | Data-source inventory and read actions |
| Create, update, replace, destroy, unchanged | Imports, moves, forgotten resources, and output changes |
| Module addresses, count, for_each, multiple working directories | Deferred plans and complete provider-alias account/region modeling |
| Unknown values and Terraform sensitivity masks | Automatic discovery of unmarked secrets |
CI tests Terraform 1.16.2 and OpenTofu 1.12.6 on Linux, macOS, and Windows. Fixtures also cover Terraform 1.14.4. Other versions may work; your CLI and provider constraints determine which configurations can be planned.
Keep it local
Terradune never runs apply. Planning can still contact AWS, data sources, remote backends, and external programs referenced by your configuration. Only run trusted projects.
The server defaults to 127.0.0.1 and has no authentication or TLS. Keep it local. Sensitive values are masked using Terraform's metadata, but unmarked secrets and diagnostics still require care.
See the security policy and release process.