Advanced patterns

  • Gitflow: Implement a Gitflow branching model with Stategraph Orchestration using destination branch tags, branch rules, and one workflow per branch.
  • Layered Runs: Order plan and apply across dependent layers of infrastructure with depends_on, so each layer runs only after the layers it depends on have applied.
  • Dynamic Configuration: Generate the repository configuration at runtime with config_builder, a script that reads the merged configuration and writes the final one.
  • Terragrunt Config Builder: Discover every Terragrunt module in a monorepo with the bundled config builder script and generate depends_on ordering from dependency blocks.
  • Custom Plan and Apply Steps: Extend plan and apply workflows with run, env, and oidc steps to add validation, security scanning, and notifications around Terraform operations.
  • Custom Runners: Choose the GitHub Actions or GitLab CI runners that execute plan and apply with the runs_on workflow key, using runner labels or runner tags.
  • Choosing an Engine: Choose the engine that runs plan and apply: Terraform, OpenTofu, the stategraph CLI, Terragrunt, Pulumi, CDKTF, or a custom command.
  • Custom File Discovery with Tree Builder: Replace Git file discovery with a tree_builder script that reports which files exist and which changed, for generated Terraform and custom rules.
  • Tags and Tag Queries: Group directories and workspaces with tags, then target them with tag queries in workflows, access control, apply requirements, and commands.
  • Locks and Concurrency: How Orchestration locks directories on apply and merge, when locks are released, how to unlock, and how to tune lock_policy per workflow.
  • Multiple Environments: Manage production, staging, and QA in one repository with separate directories, workspaces, or tfvars files, and target each with tag queries.
  • Grouping Infrastructure with Stacks: Group directories and workspaces into named stacks with plan_after, apply_after, modified_by, and auto_apply rules to build a deployment pipeline.
  • YAML Anchors: Reuse engine settings, workflow steps, access policies, and apply requirements across your configuration with YAML anchors in the definitions section.
  • GitHub Reusable Workflows: Centralize the Orchestration GitHub Actions workflow in one repository and call it from every Terraform repository with a small workflow_call caller.