Change Assurance
See whether infrastructure changes altered expected connectivity.
Understand network state, detect infrastructure changes, validate critical connectivity, and identify regressions.
Major network domains and discovered relationships.
10.10.0.0/16
2 subnets · 1 Critical Path
10.30.0.0/16
2 subnets · inspection
lab-tgw
tgw-0941
3 attachments · available
10.20.0.0/16
2 subnets · 1 Critical Path
lab-tgw route table18m
lab-b attachment2h
Sample infrastructure shown in the same hierarchy as the live Cloud Dashboard.
Terraform pre-change assurance
PingTraceSSH evaluates configured Critical Paths against proposed Terraform state before apply.
production-network · 1 / 2 Critical Paths reachable in the proposed state
Transit Gateway route to 10.0.0.0/16 is missing.
Terraform resource: aws_ec2_transit_gateway_route.b_via_inspection
Action: DELETE
Apply blocked
Mandatory enforcement returns the failed assurance result to HCP Terraform before apply.
Example analysis using supported Terraform assurance fields. No customer plan data is shown.
How it works
Read-only cross-account access.
Discover and model AWS network state.
Track meaningful network configuration changes.
Identify critical-path regressions.
What it solves
See whether infrastructure changes altered expected connectivity.
Continuously verify important network paths.
Compare before and after network state.
Understand TGW routing, attachments, and related changes.
Evaluate proposed network changes and return SAFE, REGRESSION, or INCONCLUSIVE before apply.
Available now
PingTraceSSH currently models core AWS network resources.
Azure and GCP are not currently supported.
PingTraceSSH connects through AWS STS AssumeRole with customer-specific External IDs and minimum read-only permissions.
Get network change assurance for AWS and Terraform for $299/month.
Start Founding Pilot