rudder-terraform-workflow — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited rudder-terraform-workflow (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The rudderlabs/rudderstack Terraform provider manages a RudderStack workspace as infrastructure-as-code: sources, destinations, and connections.
The user is authoring HCL for RudderStack, running terraform plan/apply against a workspace, migrating from UI-managed to Terraform-managed resources, importing existing resources, or organizing multi-env setups.
RUDDERSTACK_ACCESS_TOKEN (preferred) or in the provider blockRUDDERSTACK_API_URL (default: https://api.rudderstack.com)terraform applyterraform {
required_providers {
rudderstack = {
source = "rudderlabs/rudderstack"
version = "~> 4.4"
}
}
}
provider "rudderstack" {
# access_token = "..." # or set RUDDERSTACK_ACCESS_TOKEN env var
# api_url = "https://api.rudderstack.com"
}| Category | Count | Examples |
|---|---|---|
| Connection | 1 | rudderstack_connection — links source to destination |
| Sources | ~50 | SDK sources (JS, Android, iOS, Python, Go, etc.), webhooks, SaaS integrations |
| Destinations | ~46 | Warehouses, analytics, marketing, ad platforms, infrastructure |
No data sources are currently exposed — the provider is resource-centric.
terraform {
required_providers {
rudderstack = {
source = "rudderlabs/rudderstack"
version = "~> 4.4"
}
}
}
provider "rudderstack" {} # uses RUDDERSTACK_ACCESS_TOKEN from env
resource "rudderstack_source_javascript" "web" {
name = "my-web-app"
}
resource "rudderstack_destination_webhook" "logs" {
name = "event-logger"
config {
webhook_url = "https://logs.example.com/events"
webhook_method = "POST"
}
}
resource "rudderstack_connection" "main" {
source_id = rudderstack_source_javascript.web.id
destination_id = rudderstack_destination_webhook.logs.id
}terraform init # fetches the provider
terraform fmt # canonicalize HCL
terraform validate # schema check
terraform plan # preview; review diff with the user
terraform apply # apply to the workspaceThe provider includes bootstrap scripts to generate Terraform code from existing RudderStack resources:
# Generate Terraform configuration
RUDDERSTACK_ACCESS_TOKEN=token ./scripts/bootstrap-terraform.sh > rudderstack.tf
# Generate import commands
RUDDERSTACK_ACCESS_TOKEN=token ./scripts/bootstrap-terraform-import.sh
# Import resource state
terraform import rudderstack_source_javascript.web <source-id>
terraform import rudderstack_destination_redshift.warehouse <destination-id>Note: Sensitive credentials (API keys, secrets) are not exposed via the API and must be added manually after import.
Warehouse destinations (BigQuery, Redshift, Snowflake) support sync scheduling:
resource "rudderstack_destination_bigquery" "warehouse" {
name = "my-bigquery"
config {
project = "gcp-project-id"
bucket_name = "gcs-bucket"
credentials = base64encode(file("service-account.json"))
location = "us-east1"
prefix = "rudder_"
sync {
frequency = "30" # minutes
start_at = "10:00"
exclude_window_start_time = "11:00"
exclude_window_end_time = "12:00"
}
}
}Some destinations support connection_mode for web integrations:
config {
# ... destination config ...
connection_mode {
web = "cloud" # or "device"
}
}Destinations support multiple consent providers per platform:
config {
# ... destination config ...
consent_management {
web = [
{
provider = "oneTrust"
consents = ["analytics", "marketing"]
resolution_strategy = ""
},
{
provider = "ketch"
consents = ["analytics"]
resolution_strategy = ""
},
{
provider = "custom"
consents = ["custom_consent"]
resolution_strategy = "and" # or "or"
}
]
android = [{ provider = "ketch", consents = ["mobile"], resolution_strategy = "" }]
ios = [{ provider = "custom", consents = ["ios"], resolution_strategy = "or" }]
}
}Supported platforms: web, android, ios, unity, reactnative, flutter, cordova, amp, cloud, cloud_source, warehouse, shopify
All resources share these attributes:
| Attribute | Type | Required | Description |
|---|---|---|---|
name | String | Yes | Human-readable identifier |
enabled | Bool | No | Controls data flow (default: true) |
id | String | Read-only | RudderStack resource ID |
created_at | String | Read-only | ISO 8601 timestamp |
updated_at | String | Read-only | ISO 8601 timestamp |
Sources also expose: | write_key | String | Read-only | SDK write key for data plane |
terraform destroy against a shared/prod workspace without explicit confirmation — all sources, destinations, and connections in the state go away.tfstate to git without remote state backend encryption — it contains credentialsonetrust_cookie_categories field was replaced by consent_management block. Migrations carrying the old field silently lose consent rules.resolution_strategy or provider name are accepted by schema but silently dropped at runtime./v2 from legacy URLs for backward compatibility.RUDDERSTACK_ACCESS_TOKEN environment variable.tfstate in gitsensitive = true~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.