frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AI guardrails for Terraform. Create using natural language. Enforce in the PR

https://tryterracotta.com
7•gtlpanda•2h ago

Comments

gtlpanda•1h ago
Hey HN!

We're the cofounders of Terracotta AI, a Y Combinator S23 company. We're building AI-native guardrails for Terraform.

We help platform teams enforce best-practice standards, security, and cost control through natural language in PRs.

If you’ve ever had a Terraform plan blow up your environment because of an exposed secret, an over-permissive IAM role, or a misconfigured resource that slipped past review, you know the pain we're solving for. Senior platform engineers reviewing plan after plan, playing detective with developers, answering a non-stop influx of questions, and when something slips through the pipeline, a PagerDuty call and compliance breathing down your neck is what you get in return.

Right now, most Terraform pipelines rely on static scanners, policy engines, or manual reviews from senior engineers to catch issues. Those take forever to plan, set up, and maintain. Platform teams spend hours deciphering plan diffs, explaining blast radius to other teams, and chasing drift after it hits production.

Terracotta sits in your code source control and acts as a deterministic AI layer across your Infrastructure as Code pipeline.

When a pull request opens, pre-built or custom guardrails (using natural language to create) take action:

-- Analyzes the Terraform diff, plan, and state for risk, drift, and dependency conflicts

-- Runs cost, security, and compliance checks based on your AI-defined policies (“No public S3 buckets”, “All RDS instances must be encrypted”)

-- Summarizes the plan in simple language so reviewers and non-Terraform folks actually understand what’s changing

-- Flags high-risk changes (blast radius, cost spikes, misconfigurations) before they merge

Everything happens before CI/CD, no new runners, no custom pipelines, and no vendor lock-in. Terracotta AI reads your Terraform code, remote state, and cloud metadata contextually, so its reviews are aware of relationships between modules, dependencies, and workspaces in real-time.

We designed this for platform teams that want autonomy and speed without chaos.

You can define AI guardrails using natural language (which we translate into structured enforcement rules) and apply them at a global or per-repo level.

We also simulate deployment behavior. Think of it as a dry-run AI that tells you what will happen when terraform apply runs, including cost deltas and downstream impact.

Under the hood:

-- Deterministic, Terraform-native LLM fine-tuned on Terraform best practice, IaC best practice, compliance, and best practice cloud architecture

-- We perform plan parsing and graph dependency resolution internally — no external API calls to your code

-- Data never leaves your environment; we offer both on-prem and single tenancy deployment in addition to our cloud offering (We're SOC2 Type1/2 certified)

-- Integrates with GitHub, GitLab, and Bitbucket (coming soon) out of the box

We’re not trying to replace Terraform. We’re making it safer and faster to use at scale.

If you want to see it in action, check us out at: https://tryterracotta.com We just launched our self-service beta. 20 PRs for free, no time limit, and no CC information.

You can use our quick start tutorials to get it working in just 5 minutes: https://docs.tryterracotta.com/docs/quick-start-video-tutori...

Would love feedback, especially from folks maintaining multi-repo, mono-repo or multi-team IaC pipelines.

About the team:

I've spent over 15 years in the cloud infrastructure and observability industry, from building cloud infrastructure to deploying multi-cloud AIOps and open-source tooling. Before YC, I was the director of solutions architecture at an AIOps company (acquired by HPE).

My cofounder has over 15 years of experience building gaming, B2C, and Enterprise SaaS and our founding engineer has over 25 years of experience building B2B SaaS and has built and sold 2 startups of his own.

Growing a Language, by Guy Steele [video]

https://www.youtube.com/watch?v=_ahvzDzKdB0
1•theli0nheart•22s ago•0 comments

Understanding MCP Servers

1•ematth•1m ago•0 comments

GlassWorm: Self-propagating Worm Using Invisible Code Hits OpenVSX Marketplace

https://www.koi.ai/blog/glassworm-first-self-propagating-worm-using-invisible-code-hits-openvsx-m...
1•samuell•1m ago•0 comments

What it's like to walk across Massachusetts

https://pudding.cool/2025/10/walk/
1•surprisetalk•3m ago•0 comments

Why Nigeria Accepted GMOs

https://www.asimov.press/p/nigeria-crops
1•surprisetalk•3m ago•0 comments

The Last PCB You'll Ever Buy [video]

https://www.youtube.com/watch?v=A_IUIyyqw0M
1•surprisetalk•3m ago•0 comments

You Do It: The Four Words That Changed How I Make Every Decision

https://mindthenerd.com/why-you-do-it-the-four-words-that-changed-how-i-make-every-decision/
1•surprisetalk•3m ago•0 comments

I Built the Same App 10 Times: Evaluating Frameworks for Mobile Performance

https://www.lorenstew.art/blog/10-kanban-boards/
1•speckx•4m ago•0 comments

First Wap: A Surveillance Computer You've Never Heard Of

https://www.schneier.com/blog/archives/2025/10/first-wap-a-surveillance-computer-youve-never-hear...
1•jtbayly•6m ago•0 comments

Self-Hosting with and Without Ngrok

https://ngrok.com/blog/self-hosting-with-and-without-ngrok/
1•jakelazaroff•6m ago•0 comments

Forge: An unofficial Magic: the Gathering rules engine

https://github.com/Card-Forge/forge
2•golyi•6m ago•0 comments

Claude Code usage limit hack

https://old.reddit.com/r/ClaudeAI/comments/1oh95lh/claude_code_usage_limit_hack/
1•consumer451•9m ago•1 comments

Valkey 9.0 Debuts Multidatabase Clustering for Massive-Scale Workloads

https://thenewstack.io/valkey-9-0-debuts-multidatabase-clustering-for-massive-scale-workloads/
2•CrankyBear•11m ago•0 comments

SQLlogictest corpus (fossil-extracted mirror)

https://github.com/jzombie/sqlite-sqllogictest-corpus
1•zombiej5•12m ago•0 comments

Why do we need dithering?

https://typefully.com/DanHollick/why-do-we-need-dithering-Ut7oD4k
1•ibobev•12m ago•0 comments

Standard event schema for AI product analytics

https://www.rudderstack.com/blog/ai-product-analytics-privacy/
1•rudderdev•12m ago•0 comments

Retro Language Models: Rebuilding Karpathy's RNN in PyTorch

https://www.gilesthomas.com/2025/10/retro-language-models-rebuilding-karpathys-rnn-in-pytorch
1•ibobev•13m ago•0 comments

Useful Functions for Graphics

https://www.4rknova.com//blog/2018/07/09/01-useful-functions
1•ibobev•14m ago•0 comments

Android 16 QPR2 makes the Linux Terminal more useful with expanded file access

https://www.androidauthority.com/android-linux-terminal-expanded-file-access-3602140/
1•sipofwater•14m ago•4 comments

Admin UI and REST API for Any S3 Storage and Backup with Pocketbase

https://github.com/nativebpm/pocketbase
1•thunderbong•15m ago•0 comments

Let the little guys in: A context sharing runtime for the personalised web

https://arjun.md/little-guys
11•louisbarclay•18m ago•0 comments

React Server Components: A data-driven comparison

https://www.developerway.com/posts/react-server-components-performance
1•jakubmazanec•19m ago•0 comments

Europe simulates catastrophic solar storm to warn of real risks

https://www.space.com/astronomy/no-spacecraft-would-survive-europe-simulates-catastrophic-solar-s...
2•ljf•19m ago•0 comments

It's Not Always DNS

https://notes.pault.ag/its-not-always-dns/
1•todsacerdoti•19m ago•1 comments

House Passes Resolution Declaring "Christ Is King"

https://www.okhouse.gov/posts/news-20250418_1
2•totalZero•20m ago•1 comments

Nonmonotonic Logic

https://www.cambridge.org/core/elements/nonmonotonic-logic/C43A2C7C36750DDC1EDD2B3FDB208E2C
2•wyclif•20m ago•0 comments

A Fibre Optic Breakthrough Reveals the Universe in Sharper Detail

https://www.universetoday.com/articles/a-fibre-optic-breakthrough-reveals-the-universe-in-sharper...
1•rbanffy•22m ago•0 comments

North Korean hackers stole over $2B in crypto so far in 2025, researchers say

https://techcrunch.com/2025/10/07/north-korean-hackers-stole-over-2-billion-in-crypto-so-far-in-2...
3•PaulHoule•23m ago•0 comments

NY Sounds

https://www.gleech.org/nysound
2•paulpauper•23m ago•0 comments

National Blockchain Framework

https://www.pib.gov.in/PressReleasePage.aspx?PRID=2182023
3•testemailfordg2•24m ago•2 comments