Skip to main content

Control via git.diff on File Content

Requesting support for performing a git.diff on file content within push and/or trigger policy contexts, to enable conditional evaluation of PR and tracked runs based on the nature of the changes — especially at the field or line level.

As it stands:

  • Trigger and push policies currently provide access to lists of changed files, but not necessarily to the diff contents themselves in a structured, queryable form.

  • This makes it difficult to implement fine-grained policies that inspect how a file has changed — not just which file has changed.

  • For example, changing a description field in a .tf file is low risk, but modifying IAM permissions or backend configurations is high risk and should trigger different enforcement.

Proposed Solution

Enhance policy contexts (ideally both push and trigger, or at least push) to expose:

  • A structured version of git.diff, with access to file content diffs (not just file names).

  • The ability to inspect added, removed, or modified lines within files.

Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Aleksandra Cieslak

    Team•

    Sep 21

    Hi, thanks for the detailed writeup.

    We're closing this out for now: it's tagged as nice-to-have, has been open about a year, and hasn't picked up further interest. We don't have line-level diff content exposed in push/trigger policies today, and it's not on the near-term roadmap.

    We'll keep this on file - if more customers run into the same need for fine-grained, content-aware policy enforcement, it's a good candidate to revisit. Thanks again for the thoughtful proposal.