Skip to main content
Glama

generate_architecture_graph

Extract cloud architecture from Terraform code as a structured graph, resolving variables, grouping resources by network, and inferring connections for reasoning.

Instructions

Extract the cloud architecture of Terraform code as structured data.

Runs Terraform, resolves variables, expands count/for_each, groups resources into their VPCs, subnets and availability zones, and infers the connections between them. Use it to reason about an architecture; the diagram tools render this same graph. A tfdata.json source skips Terraform and returns in seconds.

Returns {"graphdict", "node_count", "edge_count", "provider"}, where graphdict maps each Terraform resource address to the addresses it connects to or contains; with services_only, {"services", "count", "provider"}.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
sourceYesTerraform directory, Git URL, or tfdata.json replay file. Add //folder to a Git URL for a folder inside the repository, e.g. "https://github.com/org/repo//examples". A repository whose root is a reusable module plans no resources: draw a folder that uses it instead (examples/, an environment).
upgradeNoRun `terraform init -upgrade` to refresh modules.
varfileNoPaths to .tfvars files; different var files can produce different architectures from the same code.
annotateNoPath to a terravision.yml annotation file.
planfileNoPath to an existing plan JSON (terraform show -json). With graphfile, Terraform is never run and no cloud credentials are needed.
graphfileNoPath to an existing `terraform graph` DOT file.
workspaceNoTerraform workspace to select.default
simplifiedNoDrop networking containers (VPCs, subnets, security groups) and show only the services.
services_onlyNoReturn just the deduplicated list of cloud service types instead of the full graph. Much smaller; use this first when you only need to know what a stack is built from.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
resultYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.52.0

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the behavioral burden and does well: it discloses that Terraform is actually run, variables resolved, count/for_each expanded, and connections inferred, plus a performance shortcut via tfdata.json. It omits credential/permission requirements (cloud credentials are only implied by the planfile/graphfile schema notes) and any failure modes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core verb and resource, then progressively narrower detail (processing, use case, return shapes). Every sentence earns its place, though the explicit return-shape paragraph is somewhat redundant given the output schema exists.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex 9-parameter tool with no annotations, the description covers what the tool does, how heavy it is, the alternative rendering path, and the two return variants. The presence of an output schema means return values needn't be spelled out, so the remaining gap (credentials/auth requirements) is minor.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all nine parameters well, including services_only's guidance and the planfile/graphfile no-credentials case. The description adds little parameter-level detail beyond restating the with-services_only return shape, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific verb (extract) and resource (cloud architecture of Terraform code) and describes the concrete processing performed: running Terraform, resolving variables, expanding count/for_each, grouping into VPCs/subnets/AZs. It also differentiates from siblings by stating the diagram tools render this same graph.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context ('use it to reason about an architecture') and positions the diagram tools as the rendering alternative rather than a duplicate. It also flags the fast path ('A tfdata.json source skips Terraform and returns in seconds'), but does not state explicit when-not conditions beyond that.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.