Query and insights

You can browse, search, and analyze the resources of all your Terraform states in the console, or query them with SQL. Infrastructure as a Database stores each state as a graph in PostgreSQL, and the console screens and SQL read the same tables.

Inventory

The catalog of everything Terraform manages, across all your states:

  • Instances: every resource instance, with attributes and dependencies.
  • Modules: the module hierarchy and the resources in each module.
  • Resource Types: resources grouped by type and provider.
  • Gap Analysis: cloud resources that no Terraform state manages.

Insights

Analysis of the dependency graph and its history:

  • Timeline: transaction history, who changed what and when.
  • Search: find instances by type, module, provider, address, or attribute value.
  • Blast Radius: every resource that a change can affect.
  • Graph Explorer: interactive dependency view.
  • Dashboard Metrics: what each metric on the console home page means.

SQL

Every table behind the console accepts SQL queries:

  • Query (SQL): tables, operators, JSON access, joins, and examples.
  • Dashboards: save queries as table and chart panels.

Run the same queries from the console, from the CLI with stategraph sql query, or from the API at /api/v1/mql. stategraph sql schema lists all tables and columns.

Orchestration data

With Stategraph Orchestration on, MQL also queries its GitHub and GitLab data for your tenant: runs, pull requests, gates, drift schedules, pull request stacks, unlock timestamps, and more. See Query (SQL).

Use cases

  • Infrastructure catalog: use the inventory as your CMDB, with counts by type, module, or provider.
  • Compliance and auditing: find resources by tag, attribute, region, or account, find missing required tags, make compliance reports, and see who changed what and when in the Timeline.
  • Resource discovery: find duplicate or similar resources, naming patterns, and unmanaged resources with Gap Analysis.
  • Change planning: check the impact with Blast Radius, find critical dependencies, plan a safe order, and tell stakeholders the scope.
  • Architecture: see relationships, module structure, and isolated resources in the Graph Explorer, and document your infrastructure.

Quick examples

Find all EC2 instances

In the console, see aws_instance under Inventory > Resource Types. Or run this query:

SELECT i.address, i.attributes->>'instance_type' AS instance_type
FROM instances AS i
INNER JOIN resources AS r
  ON i.resource_address = r.address AND i.state_id = r.state_id
WHERE r.type = 'aws_instance'

Count resources by type

SELECT type, count(*) AS total
FROM resources
GROUP BY type
ORDER BY type

Find untagged resources

SELECT address
FROM instances
WHERE attributes->'tags' IS NULL
  OR attributes->>'tags' = '{}'

Getting started

  1. Deploy Stategraph, if you have not already.
  2. Import your state to fill the inventory.
  3. Browse Resources to see what you have.
  4. Run a query to explore the data.