Skip to content
Back to skills

Terraform Azurerm Set Diff Analyzer

ASecurity

Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 19, 2026
documentationpythongobashazureterraformci/cddocumentation

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add ibragimov-oasis/oasis-languages-jp --skill terraform-azurerm-set-diff-analyzer --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Terraform Azurerm Set Diff Analyzer?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Terraform Azurerm Set Diff Analyzer
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ibragimov-oasis-terraform-azurerm-set-diff-analyzer/badge)](https://www.skillsdirectory.com/skills/ibragimov-oasis-terraform-azurerm-set-diff-analyzer)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: terraform-azurerm-set-diff-analyzer
description: Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.
license: MIT
tags:
  - domain/agents
  - artifact/skill
  - source/skills-copilot
---

# Terraform AzureRM Set Diff Analyzer

A skill to identify "false-positive diffs" in Terraform plans caused by AzureRM Provider's Set-type attributes and distinguish them from actual changes.

## When to Use

- `terraform plan` shows many changes, but you only added/removed a single element
- Application Gateway, Load Balancer, NSG, etc. show "all elements changed"
- You want to automatically filter false-positive diffs in CI/CD

## Background

Terraform's Set type compares by position rather than by key, so when adding or removing elements, all elements appear as "changed". This is a general Terraform issue, but it's particularly noticeable with AzureRM resources that heavily use Set-type attributes like Application Gateway, Load Balancer, and NSG.

These "false-positive diffs" don't actually affect the resources, but they make reviewing terraform plan output difficult.

## Prerequisites

- Python 3.8+

If Python is unavailable, install via your package manager (e.g., `apt install python3`, `brew install python3`) or from [python.org](https://www.python.org/downloads/).

## Basic Usage

```bash
# 1. Generate plan JSON output
terraform plan -out=plan.tfplan
terraform show -json plan.tfplan > plan.json

# 2. Analyze
python scripts/analyze_plan.py plan.json
```

## Troubleshooting

- **`python: command not found`**: Use `python3` instead, or install Python
- **`ModuleNotFoundError`**: Script uses only standard library; ensure Python 3.8+

## Detailed Documentation

- [scripts/README.md](scripts/README.md) - All options, output formats, exit codes, CI/CD examples
- [references/azurerm_set_attributes.md](references/azurerm_set_attributes.md) - Supported resources and attributes

## 🔗 Связи

- [[MOC - Skills]] — Skills library
- [[skills/skills-copilot]] — Category: skills-copilot
- [[MOC - Agents]] — Copilot agents

Files in this skill

  • SKILL.md2.4 KB
  • references/azurerm_set_attributes.json5 KB
  • references/azurerm_set_attributes.md4.1 KB
  • scripts/README.md5.4 KB
  • scripts/analyze_plan.py30.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…