Skip to content

terraform bootstrap: Layer 0 is the CI machinery only - #723

Merged
zah merged 3 commits into
devfrom
terraform/bootstrap-true-layer0-only
Oct 2, 2026
Merged

zah merged 3 commits into
devfrom
terraform/bootstrap-true-layer0-only

Conversation

@zah

@zah zah commented Oct 2, 2026

Copy link
Copy Markdown
Member

Why

Operators keep having to log in to AWS to apply Layer-0 changes that have nothing to do with running Terraform in CI. The rule this PR enforces in the shared modules:

The true bootstrap resources are the ones related to the infrastructure of running terraform plan and apply in CI, nothing else.

The full classification of every bootstrap resource in the three infra repos, the migration plan, its failure modes and the resulting login cadence are in metacraft-pm infrastructure/terraform-bootstrap-boundary.md (7d19632).

What changes

terraform/github/tf-bootstrap.nix now renders only the CI-authentication plumbing: AWS_TERRAFORM_{PLAN,APPLY,DRIFT}_ROLE_ARN and BACKEND_CONFIG_FILE. The following move to each consumer's CI-applied governance root:

  • the reviewer team, its memberships and its repository grant;
  • the sensitive-change / allow-destroy labels;
  • the production Environment;
  • the deploy branch's classic protection.

For each of those old addresses, the module emits removed { lifecycle { destroy = false } }. additionalMaintainers logins are included.

terraform/aws/tf-bootstrap.nix no longer renders the monthly budget, the 13 cost-allocation tags or the 4 cost categories. Their addresses get the same removed handling. The break-glass role stays: CI must not be able to write a role that holds AdministratorAccess.

budgetAlertEmails, manageCostAllocation, reviewerTeam, requiredStatusCheckContexts and enforceAdmins are still accepted, so existing callers evaluate unchanged. Consumers pin these modules by rev, so nothing changes for anyone until they bump. The required order is: import into the CI root first, then bump.

Driver regression test. terraform/github/tests/test-github-bootstrap-driver.sh covers plain plan / apply / outputs on a root without a governance secret manifest, with PATH-stubbed tools. It fails against 335db9d ("No github-governance-app secrets found") and passes on dev, where 0b9e93d fixed the bug. metacraft-labs/infra still pins the driver at 335db9d; the consumer PRs bump that pin.

Verification

I rendered each of the six consumer roots at its current pin and at this branch, then diffed the resources:

Root Dropped (now removed) Changed
github metacraft-prod / agent-harbor-prod team, membership, grant, 2 labels, environment, branch protection none
github blocksense-prod same + infra_maintainer_zah none
aws agent-harbor-prod budget, 13 cost-allocation tags, 4 cost categories none
aws blocksense-prod same terraform_apply_managed_iam +iam:ListInstanceProfilesForRole (old pin predates af54587)
aws metacraft-prod budget same +iam:ListInstanceProfilesForRole

Other checks:

  • terranix passes removed through, and tofu validate succeeds on the rendered GitHub example.
  • terraform/github/tests/test-bootstrap-render.sh, terraform/aws/tests/test-render.sh (extended), terraform/aws/tests/test-shared-oidc.sh and the new driver test all pass.

The bootstrap modules rendered resources the Terraform pipeline can manage
itself, so routine governance changes needed an operator AWS login.

- github/tf-bootstrap.nix renders only the CI-authentication plumbing: the
  three AWS OIDC role-ARN Actions variables and BACKEND_CONFIG_FILE. The
  reviewer team, its memberships and grant, the safety labels, the
  production Environment and the deploy branch's classic protection are org
  governance. Their old addresses are emitted as removed blocks with
  destroy = false, so a consumer that imports them into its governance root
  and then bumps this pin forgets them without touching GitHub. The retired
  arguments are still accepted.
- aws/tf-bootstrap.nix no longer renders the monthly budget, the
  cost-allocation tags or the cost categories; same removed handling. The
  break-glass role stays: CI must not be able to write a role that holds
  AdministratorAccess.
- A regression test for the github-bootstrap driver: plain plan/apply/outputs
  on a root without a governance secret manifest (the 335db9d regression,
  fixed by 0b9e93d).

Spec: metacraft-pm infrastructure/terraform-bootstrap-boundary.md
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Thanks for your Pull Request!

Below you will find a summary of the cachix status of each package, for each supported platform.

package x86_64-linux x86_64-darwin aarch64-darwin

@zah
zah merged commit 6c565de into dev Oct 2, 2026
14 of 18 checks passed
@zah
zah deleted the terraform/bootstrap-true-layer0-only branch October 2, 2026 07:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant