Query and insights
You can browse, search, and analyze the resources of all your Terraform states in the console, or query them with SQL. Infrastructure as a Database stores each state as a graph in PostgreSQL, and the console screens and SQL read the same tables.
Inventory
The catalog of everything Terraform manages, across all your states:
- Instances: every resource instance, with attributes and dependencies.
- Modules: the module hierarchy and the resources in each module.
- Resource Types: resources grouped by type and provider.
- Gap Analysis: cloud resources that no Terraform state manages.
Insights
Analysis of the dependency graph and its history:
- Timeline: transaction history, who changed what and when.
- Search: find instances by type, module, provider, address, or attribute value.
- Blast Radius: every resource that a change can affect.
- Graph Explorer: interactive dependency view.
- Dashboard Metrics: what each metric on the console home page means.
SQL
Every table behind the console accepts SQL queries:
- Query (SQL): tables, operators, JSON access, joins, and examples.
- Dashboards: save queries as table and chart panels.
Run the same queries from the console, from the CLI with stategraph sql query, or from the API at /api/v1/mql. stategraph sql schema lists all tables and columns.
Orchestration data
With Stategraph Orchestration on, MQL also queries its GitHub and GitLab data for your tenant: runs, pull requests, gates, drift schedules, pull request stacks, unlock timestamps, and more. See Query (SQL).
Use cases
- Infrastructure catalog: use the inventory as your CMDB, with counts by type, module, or provider.
- Compliance and auditing: find resources by tag, attribute, region, or account, find missing required tags, make compliance reports, and see who changed what and when in the Timeline.
- Resource discovery: find duplicate or similar resources, naming patterns, and unmanaged resources with Gap Analysis.
- Change planning: check the impact with Blast Radius, find critical dependencies, plan a safe order, and tell stakeholders the scope.
- Architecture: see relationships, module structure, and isolated resources in the Graph Explorer, and document your infrastructure.
Quick examples
Find all EC2 instances
In the console, see aws_instance under Inventory > Resource Types. Or run this query:
SELECT i.address, i.attributes->>'instance_type' AS instance_type
FROM instances AS i
INNER JOIN resources AS r
ON i.resource_address = r.address AND i.state_id = r.state_id
WHERE r.type = 'aws_instance'
Count resources by type
SELECT type, count(*) AS total
FROM resources
GROUP BY type
ORDER BY type
Find untagged resources
SELECT address
FROM instances
WHERE attributes->'tags' IS NULL
OR attributes->>'tags' = '{}'
Getting started
- Deploy Stategraph, if you have not already.
- Import your state to fill the inventory.
- Browse Resources to see what you have.
- Run a query to explore the data.