Skip to content

Add Renovate replacement rule for Azure/naming to Workleap fork - #207

Closed
Martin Charbonneau (mcharbo) wants to merge 2 commits into
mainfrom
feature/FENG-2646
Closed

Martin Charbonneau (mcharbo) wants to merge 2 commits into
mainfrom
feature/FENG-2646

Conversation

@mcharbo

@mcharbo Martin Charbonneau (mcharbo) commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

Jira issue link: FENG-2646 · rollout tracked in FENG-2988

⛔ Do not merge as-is — two corrections outstanding. See "Corrections needed" below.
Blocked on #211 (enterprise wave) landing first.

What

Adds a packageRules replacement entry to renovate-terraform-infra.json that migrates
Azure/naming/azurerm → app.terraform.io/Workleap/naming/azurerm across the autodiscovered
workleap/wl-terraform-* infrastructure repos, plus a carve-out rule that leaves the
wl-ai/modules/** instances on upstream.

Why

Azure/naming/azurerm declares two unconditional random_string resources per module
instance (random_string.main, random_string.first_letter). Only the name_unique outputs
consume them, so for nearly every consumer they are inert — but HCP Terraform bills
$0.47/month per managed resource. A full enumeration of all 455 workspaces found 4,470
random_* resources out of 27,110 billable (16.5%), ≈$2,101/month ≈ $25,200/year.

Corrections needed before this merges

  1. replacementVersion must become 1.0.1. This PR pins 1.0.0, which is the
    sha256(prefix-suffix) seed build. That design was superseded by
    workleap/terraform-azurerm-naming#3: uniqueness is now explicit via
    unique-random-string / unique-seed, and name_unique is null unless asked for.
    1.0.1 is also the only version whose tests/name_unique.tftest.hcl (7 runs) executes in
    CI — the fork repo had no INFRA_CONFIG until workleap/wl-terraform-infrastructure#1831,
    so the tests never ran before that.
  2. The "Why" paragraph in the original body described the sha256 seed and has been
    rewritten above.

Unchanged and still correct: the matchCurrentValue scoping and the wl-ai carve-out rule.

Ordering

This is the second wave. FENG-2646 measured direct consumer call sites at only ~8–15% of
the spend; the rest sits in the nested enterprise-* copies, which are covered by
renovate-terraform.json, not this file. #211 does that wave and
should land first — each enterprise module bump cuts a new module version that reaches these
consumer repos through existing Renovate anyway.

Scoping

matchCurrentValue is deliberately limited to 0.4.2/0.4.3 because the fork is cut from
upstream tag 0.4.3:

  • Lower pins (0.2.0/0.3.0/0.4.0 in wl-terraform-wlplatform) cross upstream naming
    changes that would rename live Azure resources.
  • The ~> 0.4 ranges in wl-terraform-ittech would be rewritten to ~> 1.0 rather than
    pinned.

Those six blocks are migrated by hand.

Verified since this PR was opened: the fork's main does not contain 80c13e5 "Enable
use of hyphen for API Management resources", so the APIM rename footgun is avoided; and
upstream 0.4.2 → 0.4.3 is purely additive (1,611 insertions, 0 deletions), so the 0.4.2
pins get no name change from the version jump.

wl-ai carve-out

The second rule disables the replacement for wl-ai/modules/** in wl-terraform-lab. Those
instances (app, cdn, messaging, cache, bot) feed name_unique into live storage
accounts, ServiceBus, managed Redis and a bot service; migrating them would force
destroy/recreate across ai-dev/stg/prod. Cost of the carve-out ≈$14/month. Each call site
should also get an inline comment so the exception is not silently "fixed" later.

Downstream impact

renovate-terraform-infra.json is the global config (RENOVATE_CONFIG_FILE) and forceCli
defaults true, so this rule applies to every autodiscovered repo regardless of its own
renovate.json. The workflow triggers on pull_request touching this file and the reusable
workflow exposes no dryRun input, so pushing to this branch runs the sweep for real:
expect replacement PRs in wl-terraform-{infrastructure,ittech,lab,hrtech} (~39 blocks).
#211 works around this by carrying "dryRun": "full" in its first commit; do the same here.

Expected plan shape on each consumer PR: random_string destroys only, 0 creates, 0
replacements. No moved blocks needed — the module block name is unchanged.
terraform-plan-diff will go red on those PRs; it is a commit status, not a required check,
and module replacements are not automerge-eligible, so each downstream PR needs human approval
plus code-owner review.

Remove this rule once the estate is migrated.

Copilot AI lite review requested due to automatic review settings August 5, 2026 16:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the shared Renovate configuration for autodiscovered Workleap Terraform infrastructure repositories to automatically replace the public Azure/naming/azurerm module with the Workleap fork hosted in the HCP Terraform private registry, scoped to pinned versions 0.4.2 and 0.4.3.

Changes:

  • Add a packageRules entry targeting terraform-module dependencies to replace Azure/naming/azurerm with app.terraform.io/Workleap/naming/azurerm at 1.0.0.
  • Scope the rule via matchCurrentValue to only match exact pinned versions 0.4.2 and 0.4.3.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants