Skip to content

Add manual approval gate to homelab-apply workflow - #5

Merged
nickvigilante merged 1 commit into
mainfrom
add-homelab-apply-approval-gate
May 11, 2026
Merged

Add manual approval gate to homelab-apply workflow#5
nickvigilante merged 1 commit into
mainfrom
add-homelab-apply-approval-gate

Conversation

@nickvigilante

Copy link
Copy Markdown
Owner

Summary

  • Adds github_repository_environment.homelab_apply in homelab/github.tf — required reviewer = self, branch policy restricted to protected branches.
  • Adds environment: homelab-apply to the apply job in .github/workflows/homelab-apply.yml, which makes the workflow pause for approval in the Actions UI before running tofu apply.
  • Repo-level Actions secrets stay where they are; the homelab-plan PR workflow needs them and env-secrets would override at apply time anyway if stronger isolation is ever wanted.

The Tofu resource was already applied locally (1 add, 0 change, 0 destroy), so the gate is live on origin/main once this merges.

Test plan

  • CI homelab-plan workflow passes on this PR (plan should be a no-op now that the resource exists).
  • After merge, dispatch homelab-apply from the Actions UI — confirm the run pauses at the apply job with a "Review deployments" prompt.
  • Click "Approve and deploy"; confirm the apply runs and exits clean.

Wraps the workflow_dispatch trigger in a `homelab-apply` GitHub
Environment with self as required reviewer and branch policy
restricted to protected branches. Forces an explicit approval click
in the Actions UI before apply runs against tailnet + GitHub state.

Repo-level Actions secrets are left in place so the homelab-plan PR
workflow keeps working.
@github-actions

Copy link
Copy Markdown

homelab tofu plan

Plan output
tailscale_dns_preferences.main: Refreshing state... [id=ad9f64d5-f380-ae42-4811-7604bfdb5bcd]
tailscale_dns_nameservers.global: Refreshing state... [id=34619e51-87ec-b5df-c078-fd2e3181d9c5]
data.github_user.self: Reading...
github_repository.managed["puzzles"]: Refreshing state... [id=puzzles]
github_repository.managed["vale-languagetool"]: Refreshing state... [id=vale-languagetool]
github_repository.managed["styleguide"]: Refreshing state... [id=styleguide]
github_repository.managed["passgen"]: Refreshing state... [id=passgen]
github_repository.managed["dotfiles"]: Refreshing state... [id=dotfiles]
github_repository.managed["tools"]: Refreshing state... [id=tools]
github_repository.managed["tuile"]: Refreshing state... [id=tuile]
github_repository.managed["homelab"]: Refreshing state... [id=homelab]
github_repository.managed["docs"]: Refreshing state... [id=docs]
github_repository.managed["infrastructure"]: Refreshing state... [id=infrastructure]
data.github_user.self: Read complete after 3s [id=13631471]
github_actions_secret.aws_access_key_id: Refreshing state... [id=infrastructure:AWS_ACCESS_KEY_ID]
github_repository_environment.homelab_apply: Refreshing state... [id=infrastructure:homelab-apply]
github_branch_protection.main["passgen"]: Refreshing state... [id=BPR_kwDOPAgUIM4Ek1Lp]
github_actions_secret.github_app_private_key: Refreshing state... [id=infrastructure:TF_GITHUB_APP_PRIVATE_KEY]
github_actions_secret.tailscale_oauth_client_secret: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_SECRET]
github_actions_secret.github_app_installation_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_INSTALLATION_ID]
github_branch_protection.main["tuile"]: Refreshing state... [id=BPR_kwDOSB7YJc4Ek1LN]
github_branch_protection.main["tools"]: Refreshing state... [id=BPR_kwDOCpIRFs4CjUwo]
github_branch_protection.main["puzzles"]: Refreshing state... [id=BPR_kwDOSMxZ4c4Ek1Lo]
github_branch_protection.main["homelab"]: Refreshing state... [id=BPR_kwDOSZ4rVc4Ek1bm]
github_branch_protection.main["styleguide"]: Refreshing state... [id=BPR_kwDONEbTDs4Ek1Lj]
github_branch_protection.main["dotfiles"]: Refreshing state... [id=BPR_kwDOKUP2984EclBF]
github_branch_protection.main["infrastructure"]: Refreshing state... [id=BPR_kwDOSZwzas4Ek1LQ]
github_branch_protection.main["vale-languagetool"]: Refreshing state... [id=BPR_kwDONCBpAs4Ek1LO]
github_branch_protection.main["docs"]: Refreshing state... [id=BPR_kwDOSFgwGs4Ek1Ll]
github_actions_secret.github_app_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_ID]
github_actions_secret.tailscale_oauth_client_id: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_ID]
github_actions_secret.aws_secret_access_key: Refreshing state... [id=infrastructure:AWS_SECRET_ACCESS_KEY]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.

Warning: Argument is deprecated

  with github_repository.managed["docs"],
  on github.tf line 24, in resource "github_repository" "managed":
  24:   vulnerability_alerts        = each.value.vulnerability_alerts

Use the github_repository_vulnerability_alerts resource instead. This field
will be removed in a future version.

(and 16 more similar warnings elsewhere)

@nickvigilante
nickvigilante merged commit 688f779 into main May 11, 2026
1 check passed
@nickvigilante
nickvigilante deleted the add-homelab-apply-approval-gate branch May 11, 2026 21:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant