techlite/terraform-plan
repeating is safe Reads state that changes out there — infrastructure, a remote registry. Repeating causes no effect, but the result may differ, which is why it never comes from cache.
Calcula o plano de mudanças da infraestrutura
task
How to use
oren add techlite/terraform-planInicializa o backend, calcula o plano e o grava como arquivo, para que o apply seguinte execute exatamente o que foi revisado.
Separar plano de aplicação é o ponto: sem o arquivo, o `apply` recalcularia e poderia aplicar algo diferente do que passou pela revisão.
The step the command writes
- id: terraform-plan
task: techlite/terraform-plan@^1.1.0
implementation: techlite/terraform-plan-hashicorp
dependencies:
source: ...
artifacts: ...
gcpCredential: ...
gcloudToken: ...
clusterProxy: ...What it requires from your environment
This is the floor: every implementation of this task asks for at least this.
| dependency | type | access | privilege |
|---|---|---|---|
sourceProjeto contendo os arquivos .tf. | directory | read only | low |
artifactsOnde o arquivo de plano é gravado. | directory | read and write | medium |
gcpCredentialService account com permissão de ler o estado e inspecionar os recursos. Privilégio alto: o escopo depende dos papéis da conta, e para planejar já é preciso enxergar a infraestrutura inteira. | secret-file | read only | medium |
gcloudTokenAlternative to gcpCredential: a short-lived access token (gcloud auth print-access-token), delivered as GOOGLE_OAUTH_ACCESS_TOKEN — the google provider and the GCS backend read it natively. With neither this nor gcpCredential, the runner's own identity (workload identity / ADC) carries authentication. | secret | read only | medium |
clusterProxyA SOCKS proxy that reaches a private control plane, when there is one. The worker only joins it to the step's network; the address travels into the configuration through `vars` — e.g. k8s_proxy_url: "socks5://${dependencies.clusterProxy.address}". | endpoint/tcp | read only | medium |
Inputs
directorystring- Diretório com os arquivos .tf, relativo ao workspace. default:
. workspacestring- Workspace do Terraform. Ausente, usa o default.
varFilesarray- Arquivos .tfvars, relativos ao diretório.
varsobject- Variáveis passadas diretamente, sobrepondo os arquivos.
backendConfigobject- Configuração do backend passada a `terraform init`. Para GCS, tipicamente `{ bucket: ..., prefix: ... }`.
targetarray- Recursos específicos a considerar, quando o plano é parcial.
planNamestring- Nome do arquivo de plano gravado no diretório de artefatos. default:
tfplan
Outputs
What later steps can reference.
changesboolean- Falso quando a infraestrutura já está no estado desejado.
planstring- Caminho do plano, relativo ao diretório de artefatos.
addintegerchangeintegerdestroyinteger
Implementations
Usa a imagem oficial do Terraform
ghcr.io/techlitebr/oren-terraform-hashicorp:1.1.0