Other IaC tools
Pulumi
Deltz does not parse Pulumi programs. What it reads is the preview artifact your own CI already produces.
That distinction is the whole page. If you want the short version: the gate works on Pulumi, the conventions product does not.
What works
pulumi preview --json > preview.json # your credentialed step
garboard gate --pulumi-preview preview.json .
You get two families of finding.
Change shape — plan.stateful_destroy, plan.stateful_replace, plan.blast_radius. These are the same rule ids a Terraform plan produces, because “an artifact from your CI says this database is going away” is the same fact whichever tool reported it.
Pulumi is better than Terraform here in one respect: it tells us which property forced a replacement, so the finding names it. “engineVersion cannot be changed in place” is actionable in a way that “cannot update in place” is not.
Resolved properties — the ordinary security rules, run over concrete values. This is what a preview gives that source cannot. A static parser reading publiclyAccessible: someVariable has to stay silent; the preview has already evaluated the program and says true.
On a preview containing an RDS instance and an S3 bucket, four rules fire: secops.rds_public, secops.rds_unencrypted, secops.s3_unencrypted, reliability.rds_no_backups. That is the honest count for that artifact, not a ceiling and not a promise — which rules fire depends entirely on which resource types your preview contains.
What does not work, and why
No convention derivation. Deltz’s differentiator is learning the rules your repository already keeps. That does not survive evaluation: run derivation over evaluated output and it finds the convention’s effect, not the convention. A loop that tags forty buckets reads as forty separately-tagged buckets, and “we tag buckets in a loop” — the actual rule — is exactly what was lost.
So there is no RCD for a Pulumi stack, and no conventions gate. If learning your conventions is the reason you are evaluating Deltz, Pulumi is not served by it today.
No program parsing. Supporting Pulumi programs properly means TypeScript, Python, Go and C# frontends — four parsers, each with its own evaluation semantics. Each is a product, not a feature.
Two things it deliberately will not tell you
A value that is not known until apply is not judged. Pulumi serialises those as a placeholder, and a rule that read the placeholder as a value would be firing on something that is not one. Deltz under-detects there rather than guessing.
A resource type nobody has mapped is skipped, not guessed. Pulumi type tokens (aws:rds/instance:Instance) are mapped onto the types the rule tables are keyed by. That mapping is a table, not a derivation, because a mechanical rule is wrong often enough to matter — aws:s3/bucketV2:BucketV2 is aws_s3_bucket, aws:ec2/eip:Eip is aws_eip. An unmapped token means uncovered, and nothing is reported for it.
The credential boundary
pulumi preview needs your state backend and your cloud credentials. You run it; Deltz never does. Deltz reads the file from local disk, derives findings, and never uploads, logs or persists the artifact.
The preview may contain resolved property values your program treats as sensitive. It is produced and consumed inside your own pipeline and never leaves it. Secrets Pulumi holds as secrets arrive masked, and Deltz treats a masked value as unknown rather than as evidence that no secret is there.
In GitHub Actions
- run: pulumi preview --json > preview.json
env:
PULUMI_ACCESS_TOKEN: ${{ secrets.PULUMI_ACCESS_TOKEN }}
# cloud credentials live in THIS step, not Deltz's
- uses: garboardai/garboard-action@v1
with:
pulumi-preview: preview.json
Where the evidence points
A preview carries no position in your source. Pulumi records a sourcePosition, but it points into the language runtime rather than at your file, so findings are anchored at the artifact. You get the resource by name and the reason, not a line in your TypeScript.
That is a real limitation and it is the main thing that would change if this got better. An artifact format that carried true program positions is one of the recorded triggers for revisiting the whole decision.