// pingtracessh cloud

Network Change Assurance for AWS.

Understand network state, detect infrastructure changes, validate critical connectivity, and identify regressions.

PingTraceSSH Cloud · AWS us-east-1
Example environment
3
VPCs
1
Transit Gateways
2
Healthy Paths
0
Regressions

// NETWORK TOPOLOGY

Major network domains and discovered relationships.

Discovered from latest scan
us-east-1 · Last scan: 4 minutes ago
Transit Gateway domain3 connected VPCs
lab-a PASS

10.10.0.0/16

2 subnets · 1 Critical Path

lab-inspection PASS

10.30.0.0/16

2 subnets · inspection

lab-tgw

tgw-0941

3 attachments · available

lab-b PASS

10.20.0.0/16

2 subnets · 1 Critical Path

Critical Path context2 evaluated
lab-a-to-lab-bPASS
lab-b-to-inspectionPASS
All critical network paths are healthy.
lab-a → lab-b10.20.0.0/16PASS
lab-b → lab-inspection10.30.0.0/16PASS

Recent network changes

lab-tgw route table18m

lab-b attachment2h

Sample infrastructure shown in the same hierarchy as the live Cloud Dashboard.

Terraform pre-change assurance

Know whether the proposed change is safe.

PingTraceSSH evaluates configured Critical Paths against proposed Terraform state before apply.

Example Terraform analysis
HCP Terraform · Mandatory

REGRESSION

network regression

production-network · 1 / 2 Critical Paths reachable in the proposed state

lab-a-to-lab-bREGRESSION
CURRENT:PASS→PROPOSED:FAIL

Transit Gateway route to 10.0.0.0/16 is missing.

Terraform resource: aws_ec2_transit_gateway_route.b_via_inspection

Action: DELETE

Run Task failed

Apply blocked

Mandatory enforcement returns the failed assurance result to HCP Terraform before apply.

Callback DELIVERED
View run in HCP Terraform

Example analysis using supported Terraform assurance fields. No customer plan data is shown.

How it works

From connection to validation.

  1. 01

    Connect AWS

    Read-only cross-account access.

  2. 02

    Establish Baseline

    Discover and model AWS network state.

  3. 03

    Detect Change

    Track meaningful network configuration changes.

  4. 04

    Validate Connectivity

    Identify critical-path regressions.

What it solves

Focused answers for network operations.

Change Assurance

See whether infrastructure changes altered expected connectivity.

Critical Path Validation

Continuously verify important network paths.

Incident Investigation

Compare before and after network state.

Transit Gateway Assurance

Understand TGW routing, attachments, and related changes.

Available

Terraform Pre-Change Assurance

Evaluate proposed network changes and return SAFE, REGRESSION, or INCONCLUSIVE before apply.

Available now

AWS Network Coverage

PingTraceSSH currently models core AWS network resources.

  • VPC
  • Subnets
  • Route Tables
  • Internet Gateways
  • NAT Gateways
  • Transit Gateway
  • TGW Attachments
  • TGW Route Tables
  • VPN Connections
  • Security Groups

Assurance workflow

  1. 01.Connect AWS
  2. 02.Discover network
  3. 03.View topology
  4. 04.Configure Critical Paths
  5. 05.Detect changes
  6. 06.Analyze Terraform plans
  7. 07.Classify result
  8. 08.Block unsafe changes when Mandatory

Azure and GCP are not currently supported.

Read-Only AWS Access.

PingTraceSSH connects through AWS STS AssumeRole with customer-specific External IDs and minimum read-only permissions.

View Security Architecture

Start the Founding Pilot.

Get network change assurance for AWS and Terraform for $299/month.

Start Founding Pilot