storage
storage sets where Stategraph Orchestration stores plan files, so that you control their security and access. The default is the Orchestration database. A workflow can also set storage to override the top-level value for the dirspaces that it matches.
Default Configuration
storage:
plans:
method: terrateam
Storage Methods
The method key sets how plans are stored: terrateam, s3, cmd, or none.
Server Storage
method: terrateam, the default, stores plan files in the database of the Orchestration server. It accepts no other keys.
S3-compatible Storage
method: s3 stores plans in S3-compatible storage. bucket, region, and the access keys support environment variables.
| Key | Type | Description |
|---|---|---|
bucket |
string | Bucket for the plans. Required. |
region |
string | Region of the bucket. Required. |
path |
string | Path of the plans in the bucket. Default is terrateam/plans/$dir/$workspace/$date-$time-$token. See template variables. |
access_key_id |
string | Access key ID for authentication. Optional. |
secret_access_key |
string | Secret access key for authentication. Optional. |
delete_used_plans |
boolean | Deletes the plan after use. Default is true. |
store_extra_args |
list | More arguments for aws s3 cp when it stores a plan. Optional. |
fetch_extra_args |
list | More arguments for aws s3 cp when it fetches a plan. Optional. |
delete_extra_args |
list | More arguments for aws s3 rm when it deletes a plan. Optional. |
Custom Command Storage
method: cmd runs your own commands to store, fetch, and delete plans. The commands support environment and template variables.
| Key | Type | Description |
|---|---|---|
delete |
list of strings | Command to delete the plan after use. Optional. |
fetch |
list of strings | Command to fetch the plan. Required. |
store |
list of strings | Command to store the plan. Required. |
No Persistent Plan Storage
method: none does not store the plan file after the plan workflow completes.
| Key | Type | Description |
|---|---|---|
unsafe_apply_without_plan |
boolean | Lets an apply run when no plan file was stored. Default is false. |
With false, the apply fails, because no saved plan file is available. With true, the apply evaluates the configuration again and applies that result.
The reviewed plan is not the applied plan
With method: none, Orchestration cannot apply the exact binary plan reviewed in the pull request. The apply workflow runs a new non-interactive apply. Use it only where avoiding stored plan files matters more than applying the reviewed plan.
Template Variables
Variables available during plan and apply operations:
| Variable | Description |
|---|---|
date |
Date of the plan operation, in YYYY-MM-DD format. |
dir |
Directory, for example foo/bar/baz. |
plan_path |
Path on disk of the plan. |
plan_dst_path |
Destination path on disk for a fetched plan. |
time |
Time of the plan operation, in HHMMSS format. |
token |
Unique token for the run. |
workspace |
Workspace, for example default. |
Examples
Storing Plans in AWS S3
storage:
plans:
method: s3
bucket: my-plan-bucket
region: us-west-2
access_key_id: $AWS_ACCESS_KEY_ID
secret_access_key: $AWS_SECRET_ACCESS_KEY
Custom Commands for Plan Storage
storage:
plans:
method: cmd
store: ['gsutil', 'cp', '$plan_path', 'gs://my-plan-bucket/terrateam/plans/$dir/$workspace/$date-$time-$token']
fetch: ['gsutil', 'cp', 'gs://my-plan-bucket/terrateam/plans/$dir/$workspace/$date-$time-$token', '$plan_dst_path']
delete: ['gsutil', 'rm', 'gs://my-plan-bucket/terrateam/plans/$dir/$workspace/$date-$time-$token']
Disabling Plan Storage for a Workflow
storage:
plans:
method: s3
bucket: my-plan-bucket
region: us-west-2
workflows:
- tag_query: "engine:terragrunt"
engine:
name: terragrunt
storage:
plans:
method: none
unsafe_apply_without_plan: true