Advanced patterns
- Gitflow: Implement a Gitflow branching model with Stategraph Orchestration using destination branch tags, branch rules, and one workflow per branch.
- Layered Runs: Order plan and apply across dependent layers of infrastructure with depends_on, so each layer runs only after the layers it depends on have applied.
- Dynamic Configuration: Generate the repository configuration at runtime with config_builder, a script that reads the merged configuration and writes the final one.
- Terragrunt Config Builder: Discover every Terragrunt module in a monorepo with the bundled config builder script and generate depends_on ordering from dependency blocks.
- Custom Plan and Apply Steps: Extend plan and apply workflows with run, env, and oidc steps to add validation, security scanning, and notifications around Terraform operations.
- Custom Runners: Choose the GitHub Actions or GitLab CI runners that execute plan and apply with the runs_on workflow key, using runner labels or runner tags.
- Choosing an Engine: Choose the engine that runs plan and apply: Terraform, OpenTofu, the stategraph CLI, Terragrunt, Pulumi, CDKTF, or a custom command.
- Custom File Discovery with Tree Builder: Replace Git file discovery with a tree_builder script that reports which files exist and which changed, for generated Terraform and custom rules.
- Tags and Tag Queries: Group directories and workspaces with tags, then target them with tag queries in workflows, access control, apply requirements, and commands.
- Locks and Concurrency: How Orchestration locks directories on apply and merge, when locks are released, how to unlock, and how to tune lock_policy per workflow.
- Multiple Environments: Manage production, staging, and QA in one repository with separate directories, workspaces, or tfvars files, and target each with tag queries.
- Grouping Infrastructure with Stacks: Group directories and workspaces into named stacks with plan_after, apply_after, modified_by, and auto_apply rules to build a deployment pipeline.
- YAML Anchors: Reuse engine settings, workflow steps, access policies, and apply requirements across your configuration with YAML anchors in the definitions section.
- GitHub Reusable Workflows: Centralize the Orchestration GitHub Actions workflow in one repository and call it from every Terraform repository with a small workflow_call caller.