Terraform Cloud Integration
Infrastructure-as-code run and state change audit trail for cloud security posture monitoring.
What this integration does
Terraform Cloud meets agentic SOC
Terraform Cloud and Terraform Enterprise emit audit trail events covering workspace runs, state file changes, variable set modifications, and team access changes. ManySignal ingests these events via the Terraform Cloud Audit Trail API, correlating IaC-driven infrastructure changes with cloud provider logs to detect unauthorized or anomalous infrastructure modifications.
Terraform Cloud Audit Trail API ingestion
Workspace run and plan event monitoring
State file change tracking with resource diff context
Data collected
- Workspace run events (plan, apply, destroy) with trigger and actor metadata
- State version creation and state file mutation events
- Variable and sensitive variable modification events
- Organisation and workspace settings changes
- Team membership and permission modification events
Actions supported
- Cancel a running Terraform apply via API on verdict
- Lock a Terraform workspace to prevent further runs
- Alert on sensitive variable modification
- Create Jira ticket for unauthorized infrastructure change investigation
Getting started
Set up in minutes
- 1
Generate a Terraform Cloud API token
- 2
Add the connector in ManySignal
- 3
Configure correlation rules
- 4
Set drift detection alerts
Terraform Cloud Integration: frequently asked questions
Does ManySignal support Terraform Enterprise (self-hosted)?
Yes. Configure the Terraform Enterprise base URL in the connector settings. The Audit Trail API is identical between Terraform Cloud and Enterprise.
Can ManySignal detect when Terraform destroys critical infrastructure?
Yes. Terraform destroy runs generate audit events. ManySignal alerts on destroy operations targeting resources tagged as critical or on workspaces flagged as production.
How does this compare to monitoring cloud provider logs directly?
Terraform Cloud monitoring provides intent context (who triggered the run, from which VCS commit) that cloud provider logs lack. ManySignal correlates both layers for complete visibility: Terraform as the orchestrator and the cloud API as the executor.
Can ManySignal detect unauthorised direct changes to cloud resources (bypassing Terraform)?
Yes. By comparing Terraform apply events with subsequent cloud provider API calls, ManySignal detects out-of-band changes that don't originate from a Terraform run — a classic drift and insider threat indicator.
What if sensitive variables are modified?
Terraform Cloud marks variable events as sensitive in the audit trail. ManySignal treats sensitive variable modification as a High severity event and alerts immediately.
How far back does the audit trail go?
Terraform Cloud retains audit trail events for the duration of your plan. Business and Plus plans retain 6 months; Free plan has limited retention. ManySignal preserves events per your plan's retention policy.
Does ManySignal support Terraform workspaces across multiple cloud providers?
Yes. ManySignal correlates Terraform workspace events with the appropriate cloud provider connector based on the provider configuration detected in run metadata.
Can I alert on plans that exceed a threshold number of resource changes?
Yes. Configure plan change count thresholds in ManySignal's Terraform connector settings. Plans destroying or modifying more than N resources in a production workspace trigger an alert.
How does Terraform Cloud compare to tracking Terraform Open Source?
Terraform Open Source lacks a native audit API. For self-managed Terraform, use the Terraform Enterprise connector or ingest CI/CD logs (Jenkins, GitLab CI) that run terraform commands.
Is the Terraform state file content accessible in ManySignal?
ManySignal receives state version metadata (version ID, serial, created-at) and resource change summaries, not the raw state file content. This preserves the security of sensitive data in state files.
Related integrations
Amazon Web Services Integration
Integration
Aws Cloudtrail Integration
Integration
Aws Guardduty Integration
Integration
Aws Security Hub Integration
Integration
Aws Config Integration
Integration
Aws Vpc Flow Logs Integration
Integration
Microsoft Azure Integration
Integration
Azure Activity Logs Integration
Integration
Microsoft Entra Id Integration
Integration
Microsoft Defender Integration
Integration
Microsoft Defender For Cloud Integration
Integration
Microsoft Defender For Identity Integration
Integration
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.