← docsInfrastructure

/iac

Manage Infrastructure as Code changes through deterministic plan/apply validation, policy .

Manage Infrastructure as Code changes through deterministic plan/apply validation, policy gates, and drift-aware operations.

Category

Infrastructure

Execution

7 steps, sequential + gated

Goal

Manage Infrastructure as Code changes through deterministic plan/apply validation, policy gates, and drift-aware operations.

Scope

Applies to

  • +Apply Terraform/OpenTofu change
  • +Review IaC plan
  • +Handle drift with Infrastructure as Code

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Apply Terraform/OpenTofu change""Review IaC plan""Handle drift with Infrastructure as Code""Create IaC delivery workflow"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01No `apply` without reviewed plan output.
  • 02Policy checks must pass or be explicitly waived with rationale.
  • 03State operations must be serialized and auditable.
  • 04Drift detection must be acknowledged before execution.

Procedure

  1. Step 1Step 1 — Initialize environment and validate backend/state lock readiness.
  2. Step 2Step 2 — Run format/validate checks for IaC definitions.
  3. Step 3Step 3 — Generate plan and summarize resource-level impact.
  4. Step 4Step 4 — Run policy and security checks.
  5. Step 5Step 5 — Obtain approval for apply scope.
  6. Step 6Step 6 — Execute apply and capture outputs.
  7. Step 7Step 7 — Run post-apply verification and drift snapshot.

Outputs

  • ▸IaC validation and plan report.
  • ▸Policy/security check summary.
  • ▸Apply execution evidence.
  • ▸Drift and rollback notes for handoff.

Review Gate

  • [ ]Plan is reviewed and traceable to requested change.
  • [ ]Policy/security checks are passed or justified.
  • [ ]Apply outputs and post-check evidence exist.
  • [ ]Drift status is documented.