Skip to content

Add iam_only variable and remove import blocks (#197) #47

Add iam_only variable and remove import blocks (#197)

Add iam_only variable and remove import blocks (#197) #47

name: Apply Terraform changes on merge
on:
push:
branches:
- main # or any other branch you want to trigger the deployment
paths:
- '**/*.tf'
# Recovery path for the approval gate below. When a merge-triggered apply fails
# with plan-changed, re-running it from the Actions tab replays the same push
# event and fails identically, so a manual trigger is the only way back.
workflow_dispatch:
jobs:
terraform-apply:
name: Terraform Apply
runs-on: ubuntu-latest
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write
contents: read
pull-requests: write
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::035866691871:role/devops-security-tf-apply
role-session-name: devopssecuritytfapply
aws-region: us-west-2
- name: Terraform Apply
uses: dflook/terraform-apply@v1
with:
path: terraform
backend_config_file: terraform/prod.backend.tfvars
variables: iam_only = false
auto_approve: ${{ github.event_name == 'workflow_dispatch' }}