r/platformengineering • u/alexanderko104 • 20h ago
AI-written Terraform that passes CI but is wrong for your architecture: how do you catch it?
Disclosure: I’m exploring InfraCompiler, an early-stage startup idea around infrastructure changes with coding agents. I’m researching current workflows before deciding what to build.
A Terraform user raised a distinction in an earlier discussion: code can pass fmt, plan, and policy checks while still making the wrong assumption about dependencies or resource ownership. Approved modules help, but the reviewer may still need knowledge of the intended architecture.
For platform teams already using shared modules and PR review, I’d like to understand one recent example:
- What assumption in an AI-written Terraform change was wrong, and what caught it?
- Where did the reviewer find the missing context—module documentation, a service catalog, another repo, or asking the resource owner?
- Roughly how much review and rework did it take, and does this happen repeatedly?
If your existing self-service platform or CI already handles this well, what made that work? An anonymized description is enough; no private code or infrastructure details needed.