This message was deleted.
# general
b
This message was deleted.
b
I have a minor suggestion which I think might increase the confidence of enterprises to adopt Infracost. It could be helpful in low-trust environments (e.g. banks) if Infracost published the SHA256 hashes of its hosted pricing API HTTPS cert in the docs. More interestingly, as a configuration option, specify which certificate pins (fingerprints) to trust. Why? It means you could self-host the pricing API with a self-signed certificate yet also still perform TLS validation; and users of the hosted API could also validate the Infracost backend had not been compromised (or at least not simultaneously with the cert docs!). I know that no private information is sent to Infracost. Nevertheless, the above customer environments may be wary about even hinting to a potentially untrusted party that they use cloud technology X. In summary, I think publishing pricing API certificate fingerprints, and allowing the option to accept only specific certs, would boost confidence in enterprise settings particularly and security-conscious people more generally.
👍 1
d
I understand Infracost works with terraform. Can it work with Pulumi ?
b
I would love it if Infracost helped me "net out" the important cost drivers in my breakdowns and diffs, e.g. by having fewer instances of "cost depends on usage" and omitting 0-cost line items from the breakdown.
🚀 1
w
@brave-fireman-95738 good idea! https://github.com/infracost/infracost/issues/941 sounds relevant too @damp-needle-22579 feel free to upvote https://github.com/infracost/infracost/issues/187!
b
@white-airport-8778 Yes, I think there are two sides to this, configuration for what cert is served, and configuration for which
{CA PEM,certificate fingerprint}
is trusted by the client.
👍 1
s
@white-airport-8778 I think we talked about this some time ago: would be great if Infracost could also work with ECS taskdefinitions as JSON files. We need to define them for Spinnaker, so our Terraform code is barely useful for Infracost since it has only some VPC and ECS cluster resource. The heavy lifting is done by Spinnaker for us.
w
@stocky-salesmen-15167 good reminder! ok if I create a GH issue with details from our chat to see who else is interested from the community?
🙌 1