# Triagic + Terraform: ticket investigations over your infrastructure, read-only

> Terraform in Triagic: Read HCP Terraform workspaces, runs, plans, and state versions to see what infrastructure changed.

Source: https://triagic.com/integrations/terraform

## What you can ask

- Ask Terraform which import-worker pods restarted today and why
- In Terraform, is the payments service running the version we deployed at 16:02?
- Pull the last 200 log lines from the failing container in Terraform
- Which Terraform workspace changed last week, and what did the plan touch?
- Is the consumer group for order events in Terraform lagging, and by how much?

## What the agent can do

- `list_terraform_orgs`
- `list_terraform_projects`
- `list_workspaces`
- `get_workspace_details`
- `read_workspace_tags`
- `list_runs`
- `get_run_details`
- `get_run_comments`
- `get_plan_details`
- `get_plan_logs`
- `get_plan_json_output`
- `get_apply_details`
- `get_apply_logs`
- `get_sentinel_mock`
- `list_state_versions`
- `get_state_version`
- `list_stacks`
- `get_stack_details`
- `list_workspace_policy_sets`
- `get_token_permissions`
- `list_variable_sets`
- `list_workspace_variables`

## Connect in three steps

1. **Mint a read-only credential in Terraform.** Create a dedicated user or token that can only read. Scoped to the workspace, run and state toolset with run and apply operations disabled.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Terraform. Fill in: API token (required): HCP Terraform → Account settings → Tokens. A team token scoped to read access is enough.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Terraform locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/infrastructure#terraform

## Read-only, by construction

Scoped to the workspace, run and state toolset with run and apply operations disabled.

## FAQ

**Can Triagic change anything in Terraform?**
No. Scoped to the workspace, run and state toolset with run and apply operations disabled. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Terraform?**
API token. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Terraform cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [Kubernetes](https://triagic.com/integrations/kubernetes)
- [Docker](https://triagic.com/integrations/docker)
- [Confluent / Kafka](https://triagic.com/integrations/confluent)
