Resource-Based Apply Approvals
Summary: Introduce approval workflows that trigger based on resource type or operation (e.g., destroy).
Our infra is used by both DevOps and non-DevOps teams. They want safeguards for changes that impact sensitive resources like S3 bucket policies, IAM roles, RDS, EC2, etc.
Request:
Block applies that include resource termination or modification of critical resources
Allow applies only after manual approval by specific user groups
Impact: Prevents critical mistakes by less experienced users.
- Problem
Log in to comment and vote
Comments2
Natalia Gazda
Jul 24, 2025
@Koby Yakov that’s actually already possible using approval policies. We even have an example here. Could you please check and let me know if that works for you? :) Thanks!
Black Quasar
Aug 14, 2025
Good to know, Thanks for it @Natalia Gazda