Control via git.diff on File Content
Requesting support for performing a git.diff on file content within push and/or trigger policy contexts, to enable conditional evaluation of PR and tracked runs based on the nature of the changes — especially at the field or line level.
As it stands:
Trigger and push policies currently provide access to lists of changed files, but not necessarily to the diff contents themselves in a structured, queryable form.
This makes it difficult to implement fine-grained policies that inspect how a file has changed — not just which file has changed.
For example, changing a description field in a
.tffile is low risk, but modifying IAM permissions or backend configurations is high risk and should trigger different enforcement.
Proposed Solution
Enhance policy contexts (ideally both push and trigger, or at least push) to expose:
A structured version of
git.diff, with access to file content diffs (not just file names).The ability to inspect added, removed, or modified lines within files.
Log in to comment and vote
Comments1
Aleksandra Cieslak
Sep 21
Hi, thanks for the detailed writeup.
We're closing this out for now: it's tagged as nice-to-have, has been open about a year, and hasn't picked up further interest. We don't have line-level diff content exposed in push/trigger policies today, and it's not on the near-term roadmap.
We'll keep this on file - if more customers run into the same need for fine-grained, content-aware policy enforcement, it's a good candidate to revisit. Thanks again for the thoughtful proposal.