You are learning Terraform, developing a module, or you want to run your
infrastructure tests in continuous integration without putting a single access
key in them. feint runs the Scaleway, Outscale and Exoscale APIs on your
machine. Your real clients and your real Terraform providers talk to
127.0.0.1 instead of creating billed resources.
Concretely, the demonstration takes two commands, in a cloned repository, with nothing to configure:
feint up # checks the host, starts the emulator, applies the Terraformfeint down # destroys what it created, then stops the emulatorApply complete! Resources: 2 added, 0 changed, 0 destroyed.The provider that printed that line is the real one, from the Terraform registry, in its pinned version. No account was opened, no real credential was read, and nothing keeps running anywhere but on your own workstation.
Where to start, depending on what you want to do
What feint changes concretely
A team writing Scaleway Terraform or Outscale SDK code today tests against a paying account, or does not test. The first choice turns every continuous integration run into a line on the bill, and every developer into the owner of resources forgotten when a job failed halfway. The second lets errors reach production.
An emulator answers that precise need: it replays the provider's protocol so that the official client, the one you will really use, works without leaving your machine. This site already covers the AWS equivalent with Floci; feint does the same for the three European clouds, on a single port.
For a learner, the change is elsewhere and more radical: the loop of "I write, I apply, I break it, I fix it" becomes free and immediate, where it used to require a credit card, credentials and a few minutes of provisioning on every attempt.
What you can validate, and what you cannot
This is the question to ask before installing anything, and it has a written answer rather than a promise. In short: the API contract, the Terraform lifecycle and your client's behaviour are testable; pricing, quotas, real capacity and IAM permissions are not. Some answers depend on a machine runtime installed on the host.
The three ways to run it
The workstation route, and the only one that gives access to real machines, because those rely on a runtime installed on the host. Three channels lead to the same binary:
brew install stephrobert/feint/feint # Homebrewmise use -g github:stephrobert/feint@0.13.0 # mise, with attestation verificationThe installation page covers the three channels, including the Sigstore signature-verified release, and says what each one checks before letting you run the binary.
Zero installation, control plane only. This is the form that serves in continuous integration.
docker run --rm -p 127.0.0.1:4599:4599 ghcr.io/stephrobert/feint:v0.13.0It installs the published binary, verifies its checksum before running it, and waits until the emulator answers.
- uses: stephrobert/setup-feint@b7eba1d4fcaccf65cf9124bf97a0d995996709b9 # v1.0.0 with: version: 0.13.0 provider: scalewayThe state of the project, plainly
In 0.13.0, the emulator mounts 395 operations, of which 375 are driven by a real client in the reference run; the remaining 20 state, at their route, why no official client reaches them. The three providers are not at the same point.
| Provider | Maturity | Operations | Proved by, in continuous integration |
|---|---|---|---|
| Scaleway | usable | 191 | Terraform, OpenTofu, scw |
| Exoscale | early | 104 | Terraform, OpenTofu, exo |
| Outscale | early | 100 | Terraform, OpenTofu, octl |
Usable means a realistic configuration applies, re-plans empty and destroys. Early means the protocol is right and a real client drives a real workload, but that the surface is thinner. Since 0.13.0, Terraform drives all three providers: Exoscale joined the other two with version 0.71.0 of its provider, older versions still being refused for a reason that protects you, explained in the Terraform guide.