$npx skillfedfor your agent

terraform-compliance

BDD test framework for terraform

Worth itPyPI Python ModulesReleased May 2026173.2K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — terraform_compliance-1.15.1-py2.py3-none-any.whl
v1.15.1 · released 2026-05-08 · 13 runtime deps: radish-bdd, gitpython, netaddr, colorful, filetype, junit-xml, lxml, emoji

Yes. terraform-compliance is actively maintained, has no known vulnerabilities, low install friction, and fills a genuine gap in open-source infrastructure policy testing. It is worth installing if you need to enforce compliance or security standards on Terraform code before deployment, especially in teams where policy ownership should be separated from development.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a Terraform plan in JSON format (terraform plan -out=tfplan && terraform show -json tfplan > tfplan.json); Gherkin feature files must follow radish syntax conventions.
  • Low install friction with a pure-Python wheel and 13 runtime dependencies.
  • Actively maintained with recent commits and a stable release cadence; last release 98 days ago.

License · maintenance · safety

MIT (permissive) — MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial infrastructure projects.

last release 2026-05-08 (98 days) · last repo commit 2026-05-08 · 1,459 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 173,248 downloads/mo, #10,315 on PyPI

Verify before relying

pip install terraform-compliance

Create a .feature file with Gherkin syntax:
  Given I have AWS S3 Bucket defined
  Then it must contain server_side_encryption_configuration

Run against a Terraform plan:
  terraform-compliance -p tfplan.json -f features/
  • Whether the optional faster_parsing pip install flag is available and what performance improvement it provides.
  • Specific Terraform versions supported or tested against.
  • Whether custom policy libraries or pre-built policy packs are available beyond the core framework.
Same gist for agents: .md · .json

What it is and what it does

terraform-compliance is a test framework that applies Behaviour Driven Development principles to infrastructure-as-code validation. Instead of traditional functional testing, it focuses on negative testing—ensuring your Terraform code adheres to security and compliance policies before deployment. You write policies in plain Gherkin syntax (the same language used in radish-bdd), which makes them readable to both developers and security teams. The framework parses your Terraform plan and validates it against these policies, catching violations early in your CI/CD pipeline.

The package depends on radish-bdd for feature file parsing, gitpython for repository operations, and several utilities for parsing, formatting, and caching results. It runs on multiple Python versions and operating systems, integrating easily into existing deployment pipelines or git hooks. The framework is particularly useful when you need to enforce organizational standards—such as requiring S3 bucket encryption or preventing public security group rules—without relying on enterprise Sentinel licensing.

Use it for

  • Enforce encryption requirements on cloud storage resources before they are deployed to production.
  • Validate that security groups and network ACLs follow your organization's least-privilege policies.
  • Ensure all database instances have backup and high-availability configurations defined in code.
  • Prevent creation of publicly accessible resources that should remain private.
  • Run compliance checks in CI/CD pipelines to gate infrastructure deployments.
  • Segregate policy ownership by storing feature files in a separate repository managed by a security team.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

terraform-compliance is actively maintained, has no known vulnerabilities, low install friction, and fills a genuine gap in open-source infrastructure policy testing. It is worth installing if you need to enforce compliance or security standards on Terraform code before deployment, especially in teams where policy ownership should be separated from development.

Install

terraform-compliance on PyPI

Before you install

Low install friction with a pure-Python wheel and 13 runtime dependencies. Actively maintained with recent commits and a stable release cadence; last release 98 days ago.

Requires a Terraform plan in JSON format (terraform plan -out=tfplan && terraform show -json tfplan > tfplan.json); Gherkin feature files must follow radish syntax conventions.

License in practice

MIT license permits free use, modification, and distribution with minimal restrictions, making it suitable for both open-source and commercial infrastructure projects.

Quickstart

pip install terraform-compliance

Create a .feature file with Gherkin syntax:
  Given I have AWS S3 Bucket defined
  Then it must contain server_side_encryption_configuration

Run against a Terraform plan:
  terraform-compliance -p tfplan.json -f features/

Verify before relying

  • Whether the optional faster_parsing pip install flag is available and what performance improvement it provides.
  • Specific Terraform versions supported or tested against.
  • Whether custom policy libraries or pre-built policy packs are available beyond the core framework.

Package facts

LicenseMIT permissive
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependencies
13 packages
radish-bddgitpythonnetaddrcolorfulfiletypejunit-xmllxmlemojimocksemverIPythondiskcacheorjson
MaintenanceActively maintained 98 days since the last release
Last repo commit
First released
Downloads173,248 / month, #10,315 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 4 - BetaEnvironment :: ConsoleIntended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: MacOSOperating System :: Microsoft :: WindowsOperating System :: POSIXOperating System :: UnixProgramming Language :: PythonProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: Libraries :: Python Modules

Evidence: terraform_compliance-1.15.1-py2.py3-none-any.whl

Tags

Capabilities
terraform policy testinginfrastructure compliance validationterraform security scanningBDD for infrastructure as codeterraform negative testingcompliance as code frameworkterraform plan validation
Topics
infrastructure-as-codepolicy-enforcementbdd-testing

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “terraform policy testing”

  • terraform-complianceterraform-compliance is a BDD-based test framework that validates…
  • tfparsetfparse parses and evaluates Terraform HCL configuration files using…
  • tftestWraps the Terraform executable to facilitate testing Terraform…

Give your agent the search over MCP, or paste the wish link into any chat.

More Python Modules packages

idna Worth it
PyPI · Python Modules · released Jun 2026

Converts domain names between Unicode and ASCII-compatible encoding (Punycode) according to IDNA 2008 and Unicode Technical Standard 46, with security validation and broader script coverage than the standard library.

Install it if you work with internationalized domain names, need to validate domains, or use HTTP clients that depend on it transitively.

BSD-3-Clausepure Python · 3.9+
1.8Bdownloads / mo
setuptools Worth it
PyPI · Python Modules · released Aug 2026

Setuptools is a Python build backend and package management tool that handles building, distributing, and installing Python packages, including support for C/C++ extension modules.

MITpure Python · 3.10+
1.6Bdownloads / mo
PyYAML Worth it
PyPI · Python Modules · released Sep 2025

PyYAML parses and emits YAML 1.1 data format, enabling serialization and deserialization of configuration files and Python objects to and from human-readable YAML text.

MITcompiled wheel · 3.8+
1.2Bdownloads / mo
pydantic Worth it
PyPI · Python Modules · released May 2026

Pydantic validates Python data structures against type hints, coercing and checking input at runtime to ensure it matches a declared schema.

MITpure Python · 3.9+
1.1Bdownloads / mo
annotated-types Worth it
PyPI · Python Modules · released Jul 2026

Provides reusable metadata objects for use with PEP-593 `typing.Annotated` to express common constraints like bounds, collection sizes, and predicates on types.

Install it if you use or build libraries that need to express type constraints in a standardized, inspectable way—or if you want to annotate your own types with…

MITpure Python · 3.10+
871.3Mdownloads / mo
typing-inspection Worth it
PyPI · Python Modules · released Aug 2026

Provides runtime tools to inspect and introspect Python type annotations, enabling programmatic examination of type hints at execution time.

MITpure Python · 3.10+
783.0Mdownloads / mo

See also checkov · pytest-bdd · behave · radish-bdd · terraform-local · cdktf · tftest · vedro · python-terraform · bridgecrew