OpenTremor

Packs

A pack is a Python package. Ours are no different.

A pack reads one kind of change and turns it into data that OpenTremor's rules can analyze. The official packs and yours plug in the same way, through one public interface. Your own packs work exactly like the official ones.

Official packs and yours plug in through the same public interface.

  • Same public interface
  • No core fork
  • Keep it private or publish it
pyproject.tomlthe whole registration
[tool.poetry.plugins."opentremor_core.packs"]
my-pack = "my_pack:MyPack"

Declare one entry point and pip install the package. Core discovers and registers it at startup, with no changes to OpenTremor itself.

Official packs

What OpenTremor supports today.

Each ships with its own built-in rules and runs your custom rules. Self-hosted: every pack, unlimited. Cloud: they share the 100 free analyses, then need a paid plan.

TermReadsChecks
terraform-planOutput of terraform plan, including multi-stack Terramate runsEach resource's planned end state, deduplicated by content hash
terraform-code-changeGit diffs of .tf filesWhat actually changed, block by block: approved modules, tags, security regressions
python-code-changeGit diffs of .py filesInvariants a linter can't express: tenant scoping, missing auth guards, blocking calls in async paths

Build your own

For a format we don't read yet, or a convention only you have.

The interface we useThe official packs are ordinary packages built on the same documented BasePack, with nothing held back.
No fork, no approvalImplement ingest() and get_rules(), declare one entry point, and pip install it.
Private or sharedKeep it internal for a proprietary IaC format, or publish it for anyone to install.

Rather have us build it?

If you'd rather not write and maintain the parser yourself, a custom pack for your internal IaC format or module conventions is available as a scoped Services engagement.