Policy on every
Terraform plan.
ZopNight checks every Terraform and OpenTofu plan against your policies and reports on the pull request, with the monthly cost of the change beside it. Your own GitHub check decides whether it merges. ZopNight never runs apply.
Free to start. No card. The playground just needs your work email.
TerraformOpenTofuGitHub
It decides. You enforce.
A policy decision point, never an actor on your infrastructure.
Wire it in
ZopNight opens a pull request that adds a Terraform-aware GitHub Action to your repo, with its own scoped scan token.
Check the plan
Every plan runs against the policies you attach, chosen from 70 built-in rules across security, IAM, networking, cost, reliability, Kubernetes and more, or written in Rego.
Price the change
Cost guardrails put the monthly figure in the PR: a hard cap, a total budget, or a maximum increase. Engineers see the bill before they merge.
You enforce it
Every run comes back Passed, Advisory or Blocked. A block stops the merge once you make the check required in GitHub. Overrides are allowed, and every one is audited.
Guardrails with a clear edge.
What it checks, and what it will never do.
- Scope
- Your own Terraform and OpenTofu, read from plan output on each PR and from state for an inventory scan. Declared resources are matched to what is actually running.
- Frameworks
- Rules map to CIS, PCI-DSS, SOC 2, HIPAA, NIST 800-53 and FinOps, wherever a mapping applies.
- Custom policy
- Real OPA running sandboxed Rego, with no network and no clock. It only loads when a custom policy exists.
- Boundary
- A decision point, never an actor. ZopNight does not run apply and never changes your infrastructure.
Make the cost visible before the merge.
Connect a repo and the first plan is checked on its next pull request.
Prefer to talk it through first? Book 20 minutes with the team.
- $30M+annualised cloud spend under management
- 550K+resources tracked since launch
- 20-60%off the bill in the first month
- SOC 2Type II report, plus ISO 27001
Figures published on zop.dev.