Skip to main content

Resource-Based Apply Approvals

Summary: Introduce approval workflows that trigger based on resource type or operation (e.g., destroy).
Our infra is used by both DevOps and non-DevOps teams. They want safeguards for changes that impact sensitive resources like S3 bucket policies, IAM roles, RDS, EC2, etc.
Request:

  • Block applies that include resource termination or modification of critical resources

  • Allow applies only after manual approval by specific user groups

  • Impact: Prevents critical mistakes by less experienced users.

Problem
Status: 🗑️ Archived2 comments

Log in to comment and vote

Comments2

  • Natalia Gazda

    Team•

    Jul 24, 2025

    @Koby Yakov that’s actually already possible using approval policies. We even have an example here. Could you please check and let me know if that works for you? :) Thanks!

    • Black Quasar

      •

      Aug 14, 2025

      Good to know, Thanks for it @Natalia Gazda