Skip to content

Apply a factory change to every deployment

This guide covers rolling a change out across every deployment in an IaC factory, for example a security policy update or a new platform feature that every product should pick up. For the routine case of changing one deployment, see Run a factory deployment locally.

This affects every product in the factory

A change to a factory's shared configuration applies to all of its deployments, which can run to well over a hundred products. This is Platforms Team work. Do not follow these steps unless you are confident you understand the impact of the change you are rolling out.

Prerequisites

  • Everything in Run a factory deployment locally, including cloud authentication.
  • A merged, reviewed change. Roll out from the default branch, not from a working branch.

Apply to every deployment in turn

The simplest approach targets every unit sequentially.

poe run --all apply

Terragrunt processes one unit at a time, showing an interactive plan and prompting for confirmation before moving on to the next. This is the safest option, because you see and approve every change individually. It is also slow across a large factory.

Apply to every deployment in parallel

Terragrunt can apply units in parallel, but only with -auto-approve, which removes the confirmation prompt. Our factories set TG_NO_AUTO_APPROVE to keep that prompt, so parallel applies need a different approach. Generate the plans first, review them all, then apply the saved plans.

Generate a plan file per unit. Overriding TG_NO_AUTO_APPROVE here is safe, because planning changes nothing.

rm -rf ./.terragrunt-plans && TG_NO_AUTO_APPROVE="0" poe run --all plan --out-dir ./.terragrunt-plans

Review every generated plan. This is the step that replaces the per-unit confirmation prompt, so read it properly.

TG_NO_AUTO_INIT="1" poe run --all show --out-dir ./.terragrunt-plans

Apply the plans you just reviewed.

This does not prompt for confirmation

The command below applies every saved plan without asking. Make sure you have reviewed the output of the previous step and are comfortable with every change before running it.

TG_NO_AUTO_APPROVE="0" poe run --all apply --out-dir ./.terragrunt-plans

Because each apply consumes a plan file generated in the first step, Terraform applies exactly what you reviewed. If a unit's state has changed since its plan was saved, that apply fails rather than proceeding.

See also