Skip to content

cla diff - compare HCL files against the live configuration

cla diff: shows how local HCL files differ from what is actually installed.

Same comparison as cla import, shown as a diff and with exit codes a build can act on.

Usage

cla diff <files|dirs>... [--filter PATTERN]... [--lax] [--secret-key KEY]

With no paths, ./cla-objects/<env> is read — cla -c prod diff reads ./cla-objects/prod.

Those four are the complete option set. cla diff builds its comparison with only --lax and --secret-key forwarded, so --internal, --allow-missing, --prune, --diff and --no-moved are accepted by the parser and then dropped without a word.

Output

--- clarive/generic_server.front-desk
+++ local/generic_server.front-desk
-hostname = "front.example.invalid"
+hostname = "front-new.example.invalid"

clarive/ is what the installation holds. local/ is what the files say.

An object only in the files is reported as one that would be created. An object only in the installation is reported as such and nothing is implied about deleting it — cla diff never proposes deletions.

--filter narrows the report by address, using the same patterns as cla export.

A sensitive attribute reads (sensitive) on both sides rather than showing its value. The files hold b64("…") or enc("…"), but comparing needs the real value, so by this point it has been decoded — printing it would put a live credential on your terminal and in the log of whatever ran the command. The change is still reported; only the value is withheld.

Exit codes

The same convention as git diff, so it drops into a pipeline unchanged:

  • 0 — no differences.
  • 1 — there are differences.
  • 2 — something could not be read or understood.

--filter only narrows what is shown. A conflict or an unreadable file is still exit 2 even when the filter hides the object it came from: it is a reason not to import, whether or not you asked to look at it.

Examples

Fail a build when the checked-in files have drifted from the installation:

cla diff ./cla-objects || echo "configuration has drifted"

Look at one area only:

cla diff ./cla-objects --filter 'role.*'

Comparison is semantic

Both sides are normalised the same way before being compared: an attribute left out of a file is understood as its class default, and a reference is compared as an address rather than as a stored id. A file that omits an attribute the installation stores at its default value is therefore not a difference.

See also

Clarive HCL for the language and Command line for the workflows.