/iac
Manage Infrastructure as Code changes through deterministic plan/apply validation, policy .
Manage Infrastructure as Code changes through deterministic plan/apply validation, policy gates, and drift-aware operations.
Category
Infrastructure
Execution
7 steps, sequential + gated
Goal
Manage Infrastructure as Code changes through deterministic plan/apply validation, policy gates, and drift-aware operations.
Scope
Applies to
- +Apply Terraform/OpenTofu change
- +Review IaC plan
- +Handle drift with Infrastructure as Code
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Apply Terraform/OpenTofu change""Review IaC plan""Handle drift with Infrastructure as Code""Create IaC delivery workflow"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01No `apply` without reviewed plan output.
- 02Policy checks must pass or be explicitly waived with rationale.
- 03State operations must be serialized and auditable.
- 04Drift detection must be acknowledged before execution.
Procedure
- Step 1Step 1 — Initialize environment and validate backend/state lock readiness.
- Step 2Step 2 — Run format/validate checks for IaC definitions.
- Step 3Step 3 — Generate plan and summarize resource-level impact.
- Step 4Step 4 — Run policy and security checks.
- Step 5Step 5 — Obtain approval for apply scope.
- Step 6Step 6 — Execute apply and capture outputs.
- Step 7Step 7 — Run post-apply verification and drift snapshot.
Outputs
- ▸IaC validation and plan report.
- ▸Policy/security check summary.
- ▸Apply execution evidence.
- ▸Drift and rollback notes for handoff.
Review Gate
- [ ]Plan is reviewed and traceable to requested change.
- [ ]Policy/security checks are passed or justified.
- [ ]Apply outputs and post-check evidence exist.
- [ ]Drift status is documented.