thothctl

Publish Python Package Documentation PyPI version Python 3.10+ License: Apache-2.0

ThothCTL

AI-Powered Infrastructure Lifecycle CLI for DevSecOps, Platform Engineering, and IaC governance.

ThothCTL

ThothCTL accelerates the adoption of Internal Developer Platforms by combining security scanning, inventory management, cost analysis, AI-driven code review, and organizational policy enforcement into a single CLI.

Quick Start

pip install --upgrade thothctl

# Scan for security issues
thothctl scan iac -t checkov -t trivy -t opa

# Create infrastructure inventory (SBOM)
thothctl inventory iac --check-versions

# Launch web dashboard
thothctl dashboard launch

# AI-powered security review
thothctl ai-review analyze -d ./terraform -p ollama

Key Features

🔒 Security Scanning

Multi-tool scanning with unified HTML reports and enforcement:

# All scanners with hard enforcement (fails pipeline on violations)
thothctl scan iac -t checkov -t trivy -t kics -t opa -t terraform-compliance --enforcement hard

📦 Infrastructure Inventory (SBOM)

CycloneDX 1.6 compliant Software Bill of Materials:

thothctl inventory iac --check-versions

📊 Web Dashboard

Modern FastAPI-based dashboard with dark mode:

thothctl dashboard launch

🤖 AI Agent for IaC Security

Multi-agent system for automated code review and PR decisions:

thothctl ai-review analyze -d ./terraform -p ollama
thothctl ai-review decide -d ./terraform --pr-number 42 --dry-run

💰 Cost Analysis & Risk Assessment

thothctl check iac -type cost-analysis --recursive
thothctl check iac -type blast-radius --recursive
thothctl check iac -type drift --recursive

🔄 Template Engine & Project Management

thothctl project convert --make-template --template-project-type terraform
thothctl init project -p my-infra --project-type terraform

All Commands

Command Description
scan iac Multi-tool security scanning with enforcement
inventory iac Infrastructure SBOM with version tracking
check iac Cost analysis, blast radius, drift detection, structure validation
ai-review AI-powered security analysis and PR decisions
dashboard launch Web dashboard for all reports
document iac Auto-generate documentation
project convert Template ↔ project conversion
init project Scaffold new IaC projects
mcp Model Context Protocol server
generate Generate IaC from rules and components

Installation

pip install --upgrade thothctl
Requirements: Python 3.10+ Linux, macOS, or Windows (WSL)

Optional system packages:

# Linux/Debian
sudo apt install graphviz libgraph-easy-perl -y

# macOS
brew install graphviz graph-easy

Dev Container

A ready-to-use Dev Container is available with all tools pre-configured:

# Open in VS Code → "Reopen in Container"
# Or use the devcontainer CLI:
devcontainer up --workspace-folder .

Documentation

📖 Full docs: thothforge.github.io/thothctl

CI/CD Integration

# GitHub Actions
- name: Security scan
  run: thothctl scan iac -t checkov -t trivy -t opa --enforcement hard --post-to-pr

- name: Inventory check
  run: thothctl inventory iac --check-versions --report-type json

Roadmap

📖 Full Roadmap

Contributing

Contributions welcome! See CONTRIBUTING.md for guidelines.

License

Apache-2.0