terraform bootstrap: Layer 0 is the CI machinery only - #723
Merged
Merged
Conversation
The bootstrap modules rendered resources the Terraform pipeline can manage itself, so routine governance changes needed an operator AWS login. - github/tf-bootstrap.nix renders only the CI-authentication plumbing: the three AWS OIDC role-ARN Actions variables and BACKEND_CONFIG_FILE. The reviewer team, its memberships and grant, the safety labels, the production Environment and the deploy branch's classic protection are org governance. Their old addresses are emitted as removed blocks with destroy = false, so a consumer that imports them into its governance root and then bumps this pin forgets them without touching GitHub. The retired arguments are still accepted. - aws/tf-bootstrap.nix no longer renders the monthly budget, the cost-allocation tags or the cost categories; same removed handling. The break-glass role stays: CI must not be able to write a role that holds AdministratorAccess. - A regression test for the github-bootstrap driver: plain plan/apply/outputs on a root without a governance secret manifest (the 335db9d regression, fixed by 0b9e93d). Spec: metacraft-pm infrastructure/terraform-bootstrap-boundary.md
Contributor
|
Thanks for your Pull Request! Below you will find a summary of the cachix status of each package, for each supported platform.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Operators keep having to log in to AWS to apply Layer-0 changes that have nothing to do with running Terraform in CI. The rule this PR enforces in the shared modules:
The full classification of every bootstrap resource in the three infra repos, the migration plan, its failure modes and the resulting login cadence are in metacraft-pm
infrastructure/terraform-bootstrap-boundary.md(7d19632).What changes
terraform/github/tf-bootstrap.nixnow renders only the CI-authentication plumbing:AWS_TERRAFORM_{PLAN,APPLY,DRIFT}_ROLE_ARNandBACKEND_CONFIG_FILE. The following move to each consumer's CI-applied governance root:sensitive-change/allow-destroylabels;productionEnvironment;For each of those old addresses, the module emits
removed { lifecycle { destroy = false } }.additionalMaintainerslogins are included.terraform/aws/tf-bootstrap.nixno longer renders the monthly budget, the 13 cost-allocation tags or the 4 cost categories. Their addresses get the sameremovedhandling. The break-glass role stays: CI must not be able to write a role that holdsAdministratorAccess.budgetAlertEmails,manageCostAllocation,reviewerTeam,requiredStatusCheckContextsandenforceAdminsare still accepted, so existing callers evaluate unchanged. Consumers pin these modules by rev, so nothing changes for anyone until they bump. The required order is: import into the CI root first, then bump.Driver regression test.
terraform/github/tests/test-github-bootstrap-driver.shcovers plainplan/apply/outputson a root without a governance secret manifest, with PATH-stubbed tools. It fails against 335db9d ("No github-governance-app secrets found") and passes ondev, where 0b9e93d fixed the bug. metacraft-labs/infra still pins the driver at 335db9d; the consumer PRs bump that pin.Verification
I rendered each of the six consumer roots at its current pin and at this branch, then diffed the resources:
removed)infra_maintainer_zahterraform_apply_managed_iam+iam:ListInstanceProfilesForRole(old pin predates af54587)iam:ListInstanceProfilesForRoleOther checks:
removedthrough, andtofu validatesucceeds on the rendered GitHub example.terraform/github/tests/test-bootstrap-render.sh,terraform/aws/tests/test-render.sh(extended),terraform/aws/tests/test-shared-oidc.shand the new driver test all pass.