Implement plan → approval → apply workflow for IaC runs #48

Open
opened 2025-09-01 14:21:11 +00:00 by chris · 0 comments
Owner

Description

  • Create a runner job template: init → plan (upload plan artifact to MinIO) → wait for manual approval (Forgejo comment or portal button) → apply.
  • Ensure apply runs under tenant-scoped kubeconfig.

Priority: P0
Estimate: 6 hours
Acceptance criteria

  • Plan artifact visible to owner/tenant.
  • Apply only executes after explicit approval.
  • Changes are visible in cluster and state in MinIO updated.
Description - Create a runner job template: init → plan (upload plan artifact to MinIO) → wait for manual approval (Forgejo comment or portal button) → apply. - Ensure apply runs under tenant-scoped kubeconfig. Priority: P0 Estimate: 6 hours Acceptance criteria - Plan artifact visible to owner/tenant. - Apply only executes after explicit approval. - Changes are visible in cluster and state in MinIO updated.
chris added this to the C - IaC Flow for Customers milestone 2025-09-01 14:21:11 +00:00
chris added the
ci
security
workflow
labels 2025-09-01 14:21:11 +00:00
chris self-assigned this 2025-09-01 14:21:11 +00:00
chris added this to the MVP project 2025-09-03 06:51:58 +00:00
This repository is archived. You cannot comment on issues.
No description provided.