tf-approval-gate

tf-approval-gate

Enables AI coding agents to plan, policy-check, and cost-estimate Terraform changes while requiring human approval through Slack or CLI before any terraform apply can execute.

Category
访问服务器

README

TF Approval Gate

An MCP server that lets AI coding agents (Claude Code, Cursor, etc.) plan, policy-check, and cost-estimate Terraform changes -- but makes it structurally impossible for the agent to run terraform apply without a real human clicking Approve in Slack first.

Why

AI agents can now write and run Terraform directly against real cloud accounts. An agent that can terraform apply on its own can silently destroy or misconfigure production infrastructure with no human in the loop. TF Approval Gate closes that gap: every apply requires a signed, single-use token that only a real human's Slack click (or, in dev mode, a real human at a terminal) can mint. The agent's own claim that "the human approved" is never trusted -- the server re-verifies everything itself.

How it works

  1. Agent edits .tf files, then calls tf_propose_change -- runs terraform plan, Checkov (+ OPA if configured), and Infracost (if configured), and returns one bundled proposal with a safe/needs_review/blocked recommendation.
  2. Agent calls tf_request_approval -- posts the diff + policy findings + cost to Slack with Approve/Reject buttons (or prompts on the server's terminal in APPROVAL_MODE=cli). Refuses to post at all if policy findings are blocking.
  3. Agent polls tf_check_approval_status.
  4. A human clicks Approve → the server verifies the click came from an allow-listed Slack user and mints a signed, single-use token bound to that exact plan's checksum.
  5. Agent calls tf_apply with the token. The server re-verifies signature, expiry, single-use status, the plan's binary checksum, and checks for cloud-side drift -- only then does it run terraform apply.

See docs/architecture.md and docs/security-model.md for the full design and threat model.

Quick start (local, no Slack setup needed)

git clone https://github.com/SORABH13/tf-approval-gate.git
cd tf-approval-gate
npm install
npm run build
npm run check-binaries   # confirms terraform + checkov are on PATH

Requires Terraform and Checkov on PATH. OPA/Conftest and Infracost are optional (features soft-skip if missing). Or skip installing anything and use the Docker image below, which bundles all three.

Run it in dev mode (APPROVAL_MODE=cli prints the diff to the server's terminal and waits for a y/n instead of posting to Slack -- good for a first local test, weaker guarantee than Slack, see docs/security-model.md):

APPROVAL_MODE=cli TF_APPROVAL_GATE_SECRET=$(openssl rand -hex 32) npm start

Then add it as an MCP server in Claude Code (or any MCP client):

{
  "mcpServers": {
    "tf-approval-gate": {
      "command": "node",
      "args": ["/absolute/path/to/tf-approval-gate/dist/index.js"],
      "env": {
        "APPROVAL_MODE": "cli",
        "TF_APPROVAL_GATE_SECRET": "<same secret as above>"
      }
    }
  }
}

Point your agent at examples/local-demo (uses the null/random providers, no cloud credentials required) and ask it to run tf_workspace_init → tf_propose_change → tf_request_approval → tf_apply.

Docker / devcontainer

docker build produces an image with Node, Terraform, Checkov, and Conftest (OPA) preinstalled -- no host setup beyond Docker itself.

docker build -t tf-approval-gate .
docker run --rm -it \
  -e APPROVAL_MODE=cli \
  -e TF_APPROVAL_GATE_SECRET=$(openssl rand -hex 32) \
  -v "$(pwd)/examples/local-demo":/examples/local-demo:ro \
  -v tf-approval-gate-data:/data \
  tf-approval-gate

For Slack mode, add -e SLACK_BOT_TOKEN=... -e SLACK_APP_TOKEN=... -e SLACK_APPROVAL_CHANNEL=... -e SLACK_APPROVER_USER_IDS=... and drop APPROVAL_MODE=cli. Approval state persists in the /data volume (SQLite-backed, see docs/architecture.md).

A .devcontainer/devcontainer.json is also included for VS Code / GitHub Codespaces -- open the repo in a container and terraform/checkov/conftest are ready immediately.

Slack setup (production mode)

  1. Create a Slack app from examples/slack-app-manifest.yml.
  2. Enable Socket Mode, generate an app-level token (xapp-...).
  3. Install the app to your workspace, copy the bot token (xoxb-...).
  4. Set SLACK_BOT_TOKEN, SLACK_APP_TOKEN, SLACK_APPROVAL_CHANNEL, and SLACK_APPROVER_USER_IDS (comma-separated Slack user IDs allowed to click Approve/Reject) -- see .env.example.
  5. Run with APPROVAL_MODE=slack (the default).

Full walkthrough: docs/slack-setup.md.

Tools

Tool Purpose
tf_workspace_init Checks out/copies a Terraform project into a sandboxed workdir.
tf_write_file Writes .tf/.tfvars for agents with no native filesystem access.
tf_plan terraform init && plan, returns a per-resource change summary.
tf_policy_check Checkov (+ OPA/Conftest) against the plan, merged into one report.
tf_cost_estimate Infracost monthly cost delta (skipped if unconfigured).
tf_propose_change Composite: plan + policy + cost in one call. Call this first.
tf_request_approval Posts to Slack (or CLI) for human approval.
tf_check_approval_status Poll for the signed approval token.
tf_apply The only tool that runs terraform apply. Requires a valid token.

Full reference: docs/tool-reference.md.

Status

v0.1 through v0.4 are implemented and tested: happy path (Checkov, Slack Socket Mode / CLI fallback), OPA/Conftest, Infracost cost estimation, and a SQLite-backed approval store with atomic single-use token consumption. A Docker image and devcontainer are built and verified. Real end-to-end runs have been done against both the local null/random demo and a live AWS account (examples/aws-s3-demo). See docs/architecture.md for the full roadmap and what's still open before a public launch post (a demo GIF and outside cold-testing -- see CONTRIBUTING.md).

License

MIT -- see LICENSE.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选