Déjà Vu? Redundant Dependencies in Terraform

Abstract

Infrastructure as Code (IaC) enables practitioners to provision cloud infrastructure through declarative specifications. In Terraform, developers can define explicit dependencies to enforce execution order when implicit dependencies are insufficient. However, developers may explicitly declare dependencies that are already captured by expression references. Such redundant dependencies add unnecessary complexity and, more importantly, may cause Terraform to produce overly conservative plans and unnecessarily constrain the order in which infrastructure objects are provisioned.
To enable this study, we develop depends_off, a static analysis tool for detecting redundant dependencies in Terraform configurations, and use it to analyze 76,296 repositories comprising 226,662 modules. We investigate the prevalence and characteristics of redundant dependencies and their impact on Terraform dependency graphs. We detect 89,570 redundant dependencies, affecting 17% of repositories and 10% of modules. Redundancy is strongly associated with particular resource types and providers, but not with repository-level characteristics such as size, age, or activity. Moreover, removing possibly redundant dependencies reduces the critical path in 8.6% of the cases we could measure, with a median reduction of 14.3% among affected graphs. These findings establish redundant dependencies as a recurring and potentially consequential IaC quality issue and motivate their automated detection as part of Terraform development and maintenance

Publication
In CONFLANG, 2026, Co-located with 41st IEEE/ACM International Conference on Automated Software Engineering (ASE 2026)
Avatar
Alexandra Mendes
Assistant Professor

My research focuses on encouraging a wider adoption of software verification by creating tools and methods that hide the complexities of verifying software. Much of my most recent work overlaps with the area of software engineering. For more details, see selected publications and some of my projects. Follow me on Twitter or add me on LinkedIn. See also the Software Reliability Lab website.