पाठ 24 / 25
Plan-Based Review in CI
Every change through a pull request.
fmt, validate, plan, review, apply
A common workflow: on every pull request, CI runs fmt -check, validate, linters and terraform plan -out=tfplan, posts the plan summary for review, and runs policy checks on the plan JSON. After approval and merge, CI applies the saved plan with credentials scoped to that environment (ideally short-lived OIDC credentials, not stored keys). Tools such as Atlantis, HCP Terraform, Spacelift or plain CI pipelines implement this pattern.
A pipeline outline
Adapt to your CI system.
on pull request:
terraform fmt -check -recursive
terraform init -input=false
terraform validate
tflint / checkov # lint + security rules
terraform plan -input=false -out=tfplan
terraform show -json tfplan | policy-check # e.g. block deletes of databases
post plan summary to the PR
on merge to main (per environment, with approval for prod):
terraform apply -input=false tfplan # the reviewed plan, short-lived credentialsNo applies from laptops
Route all applies through the pipeline so every change has a reviewed plan and an audit trail.
त्वरित जाँच: Why apply from CI rather than from developer laptops?
- CI is always faster
- Laptops cannot run Terraform
- Changes get a reviewed plan, consistent tooling and an audit trail
- It removes the need for state
Answer
Changes get a reviewed plan, consistent tooling and an audit trail — Process makes infrastructure changes safe.