FAQ
Answers to common questions about InfraKitchen.
Find answers to common questions about InfraKitchen.
General Questions
How is InfraKitchen different from OpenTofu/Terraform?
| InfraKitchen | OpenTofu/Terraform |
|---|---|
| GUI-based workflow | CLI-based |
| Dynamic forms for variables | Manual variable files |
| Built-in state management | Manual backend configuration |
| Audit logs and history | Limited tracking |
| Template catalog | Module registry |
| Pull request automation | Manual Git workflows |
| RBAC and approvals | No built-in access control |
Think of InfraKitchen as a layer on top of OpenTofu/Terraform that makes it more accessible and manageable.
Can I use InfraKitchen with existing OpenTofu/Terraform modules?
Absolutely! InfraKitchen works with standard OpenTofu/Terraform modules. Simply register your Git repository containing modules, and InfraKitchen will automatically analyze variables and outputs.
Technical Questions
How does InfraKitchen store OpenTofu/Terraform state?
InfraKitchen supports standard OpenTofu/Terraform backend configurations:
- AWS S3 with DynamoDB locking
- Azure Storage with blob storage
- GCP Storage with GCS buckets
- PostgreSQL with the
pgbackend (one schema per storage)
State files are stored in your configured backend, not in InfraKitchen itself. This ensures compatibility with existing OpenTofu/Terraform workflows.
Can I import existing infrastructure into InfraKitchen?
Yes, but with some manual steps:
- Create a resource in InfraKitchen with matching configuration
- Use the import command (
terraform import/tofu import) to bring existing infrastructure into the state - Run a dry run to verify configuration matches
How does variable inheritance work?
Child resources can automatically reference parent resource outputs:
# Parent VPC outputs
vpc_id: vpc-abc123
subnet_ids: [subnet-111, subnet-222]
# Child RDS resource automatically gets
vpc_id: vpc-abc123 (from parent VPC)
subnet_ids: [subnet-111, subnet-222] (from parent VPC)
This is configured in the Template Version variable configurations.
What happens if provisioning fails?
- Resource state remains
provision - Status changes to
error - Error details are logged
- You can review logs to diagnose the issue
- Fix the problem (update variables, fix integration, etc.)
- Click Retry to attempt again
How are credentials secured?
InfraKitchen uses multiple security layers:
- At Rest: Credentials encrypted in database
- In Transit: HTTPS/TLS for all communications
- In Memory: Credentials only decrypted when needed
- Access Control: RBAC limits who can view/use integrations
- Audit: All credential access is logged
Does InfraKitchen support drift detection?
Drift detection is on the roadmap.
Usage Questions
How do I know which template to use?
- Check template description - Explains what it does
- View parent/child relationships - Understand dependencies
- Look at existing resources - See how others used it
- Ask your platform team - They defined the templates
- Read documentation - Check internal wiki or docs
Why can’t I change certain variables?
Some variables are marked as “frozen” or “immutable” because:
- The underlying cloud resource cannot be modified in-place
- Changing them would require resource recreation
- They’re inherited from parent resources
- Platform team locked them for compliance
Examples: VPC CIDR blocks, RDS engine type, storage account name
What’s the difference between State and Status?
State represents the resource lifecycle:
provision- Not yet createdprovisioned- Created and runningdestroy- Marked for deletiondestroyed- Removed
Status represents the current operation:
ready- Ready for actionin_progress- Currently executingdone- Operation completederror- Operation failed
Can I provision multiple resources simultaneously?
Yes! InfraKitchen processes resources in parallel when possible. However:
- Parent resources must complete before children
- Dependent resources wait for their dependencies
- Each resource runs in an isolated environment
Why is my resource waiting for approval?
Your organization may have approval workflows enabled:
- Production resources - Require senior engineer approval
- Costly resources - Need budget owner approval
- Security-sensitive - Need security team review
Check with your platform team about approval policies.
How do I rollback a failed update?
InfraKitchen doesn’t have automatic rollback, but you can:
- Edit resource variables back to previous values
- Perform dry run to verify changes
- Apply the update
For critical situations:
- Use cloud provider console to manually roll back
- Destroy and recreate resource
- Restore from backup (for stateful resources)
Workspace Questions
Do I need to approve Pull Requests?
It depends on your workflow:
Manual Approval:
- Review PR in Git provider
- Approve and merge manually
Auto-Approval:
- Click Approve in InfraKitchen
- InfraKitchen auto-merges PR
- Code lands in default branch
No Workspace:
- Skip PR workflow entirely
- Code not synced to Git
What if PR conflicts with main branch?
Resolve conflicts:
- Navigate to workspace repository
- Pull both branches locally
- Resolve merge conflicts
- Push resolution
- Merge PR
Or:
- Delete the branch and recreate resource
- This generates a fresh PR
Can I edit workspace code directly?
You can, but be careful:
✅ Safe edits:
- Update README or documentation
- Add additional modules
- Modify resource tags
❌ Dangerous edits:
- Change variable values (creates drift)
- Modify backend configuration
- Remove InfraKitchen-generated files
Troubleshooting
Resource stuck at “in_progress”
Possible causes:
- Long-running operation - EKS clusters take 15-20 min
- Network timeout - Check connectivity
- State lock - Another operation has locked state
- Task failure - Check execution logs
Solutions:
- Wait if it’s a long operation
- Check logs for errors
- Verify integration credentials
- Contact platform team if stuck >30 min
“Parent resource not ready” error
Cause: Parent resource is not in provisioned state.
Solutions:
- Wait for parent to finish provisioning
- Check parent resource status
- Ensure parent provisioned successfully
- If parent failed, fix and provision it first
Integration authentication fails
Possible causes:
- Expired credentials
- Incorrect configuration
- Insufficient permissions
- Network connectivity issues
Solutions:
- Test integration in InfraKitchen
- Verify credentials in cloud provider
- Check IAM role/service principal permissions
- Review audit logs for detailed errors
- Update integration with new credentials
Variables not appearing in form
Cause: Template version analysis failed or variables not defined in variables.tf.
Solutions:
- Verify
variables.tfexists in module - Check OpenTofu/Terraform syntax is valid
- Re-analyze template version
- Check module folder path is correct
- Review template version logs
Dry run shows unexpected changes
Possible causes:
- Drift between state and actual infrastructure
- Variables changed since last apply
- Template version updated
- Dependencies changed
Solutions:
- Review the plan carefully
- Check if changes are intentional
- Verify variable values
- Consider running refresh-only plan
- Contact platform team if unsure
Workspace PR not created
Possible causes:
- Workspace not configured
- Git integration lacks permissions
- Repository doesn’t exist
- Branch already exists
- API rate limiting
Solutions:
- Verify workspace is set on resource
- Check Git integration has write access
- Ensure repository exists
- Delete existing branch if conflict
- Check workspace sync logs
“State lock” error
Cause: Another operation is using the OpenTofu/Terraform state.
Solutions:
- Wait for other operation to complete
- Check if another resource is provisioning
- Verify no manual OpenTofu/Terraform operations running
- Force-unlock state (last resort, dangerous)
- Contact platform team
Security Questions
How are secrets managed?
InfraKitchen:
- Encrypts secrets at rest in database
- Uses HTTPS/TLS for all communication
- Never logs sensitive values
- Masks secrets in UI and logs
- Supports cloud secret managers (AWS Secrets Manager, GCP Secret Manager) and custom encrypted key-value secrets — see Secrets
Who can see my resources?
Access control is role-based:
- Creators - Full access to their resources
- Team members - Access based on team membership
- Admins - Access to all resources
- Viewers - Read-only access
Check with your platform team about specific policies.
Can I restrict certain templates?
Yes! Platform engineers can:
- Disable templates (make unavailable)
- Set RBAC policies per template
- Require approvals for certain templates
- Limit templates to specific teams
Are audit logs available?
Yes! InfraKitchen logs:
- Resource creation/updates/destruction
- User actions and timestamps
- Integration usage
- Variable changes
- Approval decisions
- Workspace sync operations
Logs are searchable and exportable.
Cost Questions
How much does InfraKitchen cost?
InfraKitchen itself is open source and free. You pay for:
- Cloud infrastructure InfraKitchen provisions
- Compute resources to run InfraKitchen
- Storage for OpenTofu/Terraform state
- Git repository hosting (if using private repos)
Can InfraKitchen help reduce costs?
Yes, in several ways:
- Lifecycle management - Easy to destroy unused resources
- Templated configurations - Right-sizing enforced by platform team
- Audit trail - Track resource usage and owners
- Tag enforcement - Better cost allocation
- Visibility - See all resources in one place
How do I track resource costs?
- Use labels to tag resources with cost centers
- Export resource list with tags
- Use cloud provider cost allocation tags
- Set up cloud cost management tools
- Review resources periodically
Support
Can I request features?
Absolutely!
- Check GitHub Issues for existing requests
- Create a new feature request issue
- Consider contributing the feature yourself
Limitations and Constraints
What are current limitations?
- Drift Detection: Not implemented yet
- Multi-Region: Each region needs separate resources
- Custom Providers: OpenTofu/Terraform only
- Real-time Collaboration: Single user edits at a time
Supported OpenTofu/Terraform versions?
- OpenTofu/Terraform
1.10+
Still Have Questions?
Can’t find what you’re looking for?
- Open a GitHub Issue