Apply a factory change to every deployment¶
This guide covers rolling a change out across every deployment in an IaC factory, for example a security policy update or a new platform feature that every product should pick up. For the routine case of changing one deployment, see Run a factory deployment locally.
This affects every product in the factory
A change to a factory's shared configuration applies to all of its deployments, which can run to well over a hundred products. This is Platforms Team work. Do not follow these steps unless you are confident you understand the impact of the change you are rolling out.
Prerequisites¶
- Everything in Run a factory deployment locally, including cloud authentication.
- A merged, reviewed change. Roll out from the default branch, not from a working branch.
Apply to every deployment in turn¶
The simplest approach targets every unit sequentially.
poe run --all apply
Terragrunt processes one unit at a time, showing an interactive plan and prompting for confirmation before moving on to the next. This is the safest option, because you see and approve every change individually. It is also slow across a large factory.
Apply to every deployment in parallel¶
Terragrunt can apply units in parallel, but only with -auto-approve, which removes the
confirmation prompt. Our factories set TG_NO_AUTO_APPROVE to keep that prompt, so parallel applies
need a different approach. Generate the plans first, review them all, then apply the saved plans.
Generate a plan file per unit. Overriding TG_NO_AUTO_APPROVE here is safe, because planning
changes nothing.
rm -rf ./.terragrunt-plans && TG_NO_AUTO_APPROVE="0" poe run --all plan --out-dir ./.terragrunt-plans
Review every generated plan. This is the step that replaces the per-unit confirmation prompt, so read it properly.
TG_NO_AUTO_INIT="1" poe run --all show --out-dir ./.terragrunt-plans
Apply the plans you just reviewed.
This does not prompt for confirmation
The command below applies every saved plan without asking. Make sure you have reviewed the output of the previous step and are comfortable with every change before running it.
TG_NO_AUTO_APPROVE="0" poe run --all apply --out-dir ./.terragrunt-plans
Because each apply consumes a plan file generated in the first step, Terraform applies exactly what you reviewed. If a unit's state has changed since its plan was saved, that apply fails rather than proceeding.
See also¶
- Run a factory deployment locally covers the single-deployment workflow and the prerequisites shared with this guide.
- Understanding the Platforms Team's IaC factory pattern explains why each deployment has isolated state, and how nightly drift detection catches changes made outside this process.