SkillByAIOpen interactive version →

Lesson 24 / 25

Plan-Based Review in CI

Every change through a pull request.

fmt, validate, plan, review, apply

A common workflow: on every pull request, CI runs fmt -check, validate, linters and terraform plan -out=tfplan, posts the plan summary for review, and runs policy checks on the plan JSON. After approval and merge, CI applies the saved plan with credentials scoped to that environment (ideally short-lived OIDC credentials, not stored keys). Tools such as Atlantis, HCP Terraform, Spacelift or plain CI pipelines implement this pattern.

A pipeline outline

Adapt to your CI system.

on pull request:
  terraform fmt -check -recursive
  terraform init -input=false
  terraform validate
  tflint / checkov                      # lint + security rules
  terraform plan -input=false -out=tfplan
  terraform show -json tfplan | policy-check   # e.g. block deletes of databases
  post plan summary to the PR
on merge to main (per environment, with approval for prod):
  terraform apply -input=false tfplan  # the reviewed plan, short-lived credentials

No applies from laptops

Route all applies through the pipeline so every change has a reviewed plan and an audit trail.

Quick check: Why apply from CI rather than from developer laptops?

  • CI is always faster
  • Laptops cannot run Terraform
  • Changes get a reviewed plan, consistent tooling and an audit trail
  • It removes the need for state
Answer

Changes get a reviewed plan, consistent tooling and an audit trail — Process makes infrastructure changes safe.