M ManySignal
MS
TF
Integration

Terraform Cloud Integration

Infrastructure-as-code run and state change audit trail for cloud security posture monitoring.

What this integration does

Terraform Cloud meets agentic SOC

Terraform Cloud and Terraform Enterprise emit audit trail events covering workspace runs, state file changes, variable set modifications, and team access changes. ManySignal ingests these events via the Terraform Cloud Audit Trail API, correlating IaC-driven infrastructure changes with cloud provider logs to detect unauthorized or anomalous infrastructure modifications.

Terraform Cloud Audit Trail API ingestion

Workspace run and plan event monitoring

State file change tracking with resource diff context

Data collected

  • Workspace run events (plan, apply, destroy) with trigger and actor metadata
  • State version creation and state file mutation events
  • Variable and sensitive variable modification events
  • Organisation and workspace settings changes
  • Team membership and permission modification events

Actions supported

  • Cancel a running Terraform apply via API on verdict
  • Lock a Terraform workspace to prevent further runs
  • Alert on sensitive variable modification
  • Create Jira ticket for unauthorized infrastructure change investigation

Getting started

Set up in minutes

  1. 1

    Generate a Terraform Cloud API token

  2. 2

    Add the connector in ManySignal

  3. 3

    Configure correlation rules

  4. 4

    Set drift detection alerts

Terraform Cloud Integration: frequently asked questions

Does ManySignal support Terraform Enterprise (self-hosted)?

Yes. Configure the Terraform Enterprise base URL in the connector settings. The Audit Trail API is identical between Terraform Cloud and Enterprise.

Can ManySignal detect when Terraform destroys critical infrastructure?

Yes. Terraform destroy runs generate audit events. ManySignal alerts on destroy operations targeting resources tagged as critical or on workspaces flagged as production.

How does this compare to monitoring cloud provider logs directly?

Terraform Cloud monitoring provides intent context (who triggered the run, from which VCS commit) that cloud provider logs lack. ManySignal correlates both layers for complete visibility: Terraform as the orchestrator and the cloud API as the executor.

Can ManySignal detect unauthorised direct changes to cloud resources (bypassing Terraform)?

Yes. By comparing Terraform apply events with subsequent cloud provider API calls, ManySignal detects out-of-band changes that don't originate from a Terraform run — a classic drift and insider threat indicator.

What if sensitive variables are modified?

Terraform Cloud marks variable events as sensitive in the audit trail. ManySignal treats sensitive variable modification as a High severity event and alerts immediately.

How far back does the audit trail go?

Terraform Cloud retains audit trail events for the duration of your plan. Business and Plus plans retain 6 months; Free plan has limited retention. ManySignal preserves events per your plan's retention policy.

Does ManySignal support Terraform workspaces across multiple cloud providers?

Yes. ManySignal correlates Terraform workspace events with the appropriate cloud provider connector based on the provider configuration detected in run metadata.

Can I alert on plans that exceed a threshold number of resource changes?

Yes. Configure plan change count thresholds in ManySignal's Terraform connector settings. Plans destroying or modifying more than N resources in a production workspace trigger an alert.

How does Terraform Cloud compare to tracking Terraform Open Source?

Terraform Open Source lacks a native audit API. For self-managed Terraform, use the Terraform Enterprise connector or ingest CI/CD logs (Jenkins, GitLab CI) that run terraform commands.

Is the Terraform state file content accessible in ManySignal?

ManySignal receives state version metadata (version ID, serial, created-at) and resource change summaries, not the raw state file content. This preserves the security of sensitive data in state files.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.