Skip to content

Separate plan and apply roles for incubator terraform #146

Description

@ale210

Overview

To reduce risk and not allow terraform plan operations to make changes, we should separate the plan and apply roles that incubator assumes for various operations

Action Items

  • in the devops-security repo, create the role incubator-tf-plan, with the ReadOnlyAccess policy applied. The trust policy, should remain the same as the existing gha-incubator role
  • in the role-to-assume in `/.github/workflows/terraform-plan.yaml', change the role to the newly created role in the previous step
  • in the devops-security repo, create the role incubator-tf-apply, with the AdminstatorAccess policy applied. The trust policy should only include "repo:hackforla/incubator:ref:refs/heads/main",
  • in the role-to-assume in `/.github/workflows/terraform-apply.yaml', change the role to the newly created role in the previous step

Activity

  1. self-assigned this
    on Feb 19, 2026
  2. added theissue type on Feb 19, 2026
  3. moved this from New Issue Review to In progress (actively working) in CoP: DevOps: Project Boardon Feb 19, 2026
  4. added this to the 02 security milestone on Feb 19, 2026
  5. Benettonkkb commented on Feb 19, 2026

    @Benettonkkb
    Member

    Added YAML changes in this PR

  6. moved this from In progress (actively working) to Done in CoP: DevOps: Project Boardon Aug 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

Relationships

None yet

Development

No branches or pull requests

Issue actions