PR-level blast-radius guard for changes that fan out across many stacks
Problem
Plan policies evaluate one stack's plan at a time. A PR that edits a shared file (a module, a Terragrunt root .hcl, shared variables) can trigger runs on dozens or hundreds of stacks. Each plan looks small on its own, so per-stack deny and warn rules pass. Nothing in Spacelift sees the aggregate: how many stacks are affected, and how many destroys and replaces they add up to.
The failure mode is a one-line diff to a shared file that replaces resources in every environment and gets approved because no single plan looked dangerous.
Outcome
Once every run triggered by a PR has finished planning, evaluate the combined change: stacks affected, total destroys and replaces, and changes to named resource types. Above a threshold set per space, hold the tracked runs from that commit until named approvers confirm. Report the result as a single status check on the PR so it can be a required check.
Out of scope
Destroy limits on a single stack. Plan policies already handle this.
Run priority for fan-out changes. Covered by Automatically lower run priority for high fan-out changes.
- Workaround
- Problem
Log in to comment and vote
No comments yet
Be the first to share your thoughts.