Skip to main content

Extending Policy Input Data to Isolate PR-Specific Resource Changes

You provided Require commits to be reasonably sized Policy, which is useful, but we want to see if there is a way to support compare the proposed run’s resource change with current status’s of the stack so we can only alert on resource changes on this specific PR instead of including resource changed from drift or un-applied tracked run.

This may need to add more data information in input_data.

Workaround
no
Status: 🗑️ Archived2 comments

Log in to comment and vote

Comments2

  • Black Breeze

    •

    Jun 10, 2025

    Archiving due to inactivity.

  • Black Breeze

    •

    May 7, 2025

    Thanks for bringing this up—it’s a thoughtful idea, and we understand the motivation behind it. That said, it’s important to clarify that what you’re asking for—isolating resource changes caused exclusively by this PR—is technically out of reach given how Terraform (and similar tools) actually work.

    Terraform plans operate on the current live state, not a version-controlled baseline. They show what would happen if applied right now, based on the current state of infrastructure—which may include drift, unapplied runs, or changes from other sources. There’s no way to “subtract” those effects reliably from the plan output, because Terraform doesn’t label changes by source or intent.

    The challenge you’re surfacing often shows up when the code being planned isn’t aligned with what’s already been applied—e.g., pending applies or base branches not fully merged. In those cases, the plan output naturally reflects more than just the PR itself.

    We’d love to understand the underlying job to be done here. Is the goal to reduce noise in alerts? Make it easier to review PRs? Ensure change provenance for compliance? If we can focus on the outcome you’re trying to drive, there may be other, simpler ways to help—without needing Terraform to behave differently than it does.

    Let us know what success would look like in your words—we’re all ears.