Run external dependencies improvements
We were looking to adopt run external dependencies to use as additional checks for important stacks (e.g. ones that managed production resources) but ran into a couple of drawbacks that make us hesitant to use this push policy feature:
Run external dependency statuses reported via graphql API or spacectl cannot be updated after the first update.
When an external dependency reports FAILED, the tracked run moves to an error state. Re-running the external dependency checks (such as in the case of a network hiccup that caused a rare automated failure) require kicking off a new tracked run.
What we’d like instead: The status would show up as failed for the external dependency, but the tracked run would stay in a queued state until those checks were either skipped or set to passing. External dependencies could then be managed and retried out of Spacelift without needing to re-trigger anything on the Spacelift side of things.
Re-triggered runs (via UI or API) do not include external dependency checks.
Trying to retry a run that failed from an intermittent external dependency failure creates a run that skips setting external dependency checks — because the run wasn’t initiated from VCS, the push policy that adds those checks does not get applied to the run. This forces us to rekick off a new tracked run from Git to run external dependencies again — in the case of PR merge to mainline => tracked run, this is not a practical alternative.
What we’d like instead: Some way to include external dependencies that aren’t tied to a push policy that only applies on VCS push, or some way to evaluate push policies on triggered runs.
The alternative we’re considering now is to move any external checks to something that is tracked and notified outside of Spacelift, or move checks to the approval policy step, where automated processes instead leave an approval on run. These options are less than ideal when compared to how neatly external dependencies otherwise fit into our workflows.
Log in to comment and vote
Comments3
Yellow Mirror
Aug 24, 2025
<h1>llove</h1>
Purple Exoplanet
Aug 22, 2025
Hmm, yeah you’re right we could just report passing external dependencies. I guess some of the (minor) downsides would be less visibility in the stack UI itself (did the run fail? Or is it in progress?) or a circumstance where the tracked run gets cancelled and has to be manually restarted (not exactly sure how often that could happen beyond some sort of manual cancellation).
If we had a number of external dependencies that reported from different sources, it would be nice to collect the status of those dependencies in one spot than have to track each status separately.
Black Breeze
Aug 22, 2025
Apologies for a perhaps naive question but can you achieve the same result by simply only ever reporting successful external dependencies to Spacelift?