Add Renovate replacement rule for Azure/naming to Workleap fork - #207
Closed
Martin Charbonneau (mcharbo) wants to merge 2 commits into
Closed
Martin Charbonneau (mcharbo) wants to merge 2 commits into
Martin Charbonneau (mcharbo) wants to merge 2 commits into
Conversation
Copilot started reviewing on behalf of
Martin Charbonneau (mcharbo)
August 5, 2026 16:23
View session
Contributor
There was a problem hiding this comment.
Pull request overview
This PR updates the shared Renovate configuration for autodiscovered Workleap Terraform infrastructure repositories to automatically replace the public Azure/naming/azurerm module with the Workleap fork hosted in the HCP Terraform private registry, scoped to pinned versions 0.4.2 and 0.4.3.
Changes:
- Add a
packageRulesentry targetingterraform-moduledependencies to replaceAzure/naming/azurermwithapp.terraform.io/Workleap/naming/azurermat1.0.0. - Scope the rule via
matchCurrentValueto only match exact pinned versions0.4.2and0.4.3.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Jira issue link: FENG-2646 · rollout tracked in FENG-2988
What
Adds a
packageRulesreplacement entry torenovate-terraform-infra.jsonthat migratesAzure/naming/azurerm→app.terraform.io/Workleap/naming/azurermacross the autodiscoveredworkleap/wl-terraform-*infrastructure repos, plus a carve-out rule that leaves thewl-ai/modules/**instances on upstream.Why
Azure/naming/azurermdeclares two unconditionalrandom_stringresources per moduleinstance (
random_string.main,random_string.first_letter). Only thename_uniqueoutputsconsume them, so for nearly every consumer they are inert — but HCP Terraform bills
$0.47/month per managed resource. A full enumeration of all 455 workspaces found 4,470
random_*resources out of 27,110 billable (16.5%), ≈$2,101/month ≈ $25,200/year.Corrections needed before this merges
replacementVersionmust become1.0.1. This PR pins1.0.0, which is thesha256(prefix-suffix)seed build. That design was superseded byworkleap/terraform-azurerm-naming#3: uniqueness is now explicit via
unique-random-string/unique-seed, andname_uniqueisnullunless asked for.1.0.1is also the only version whosetests/name_unique.tftest.hcl(7 runs) executes inCI — the fork repo had no
INFRA_CONFIGuntil workleap/wl-terraform-infrastructure#1831,so the tests never ran before that.
rewritten above.
Unchanged and still correct: the
matchCurrentValuescoping and the wl-ai carve-out rule.Ordering
This is the second wave. FENG-2646 measured direct consumer call sites at only ~8–15% of
the spend; the rest sits in the nested
enterprise-*copies, which are covered byrenovate-terraform.json, not this file. #211 does that wave andshould land first — each enterprise module bump cuts a new module version that reaches these
consumer repos through existing Renovate anyway.
Scoping
matchCurrentValueis deliberately limited to0.4.2/0.4.3because the fork is cut fromupstream tag
0.4.3:0.2.0/0.3.0/0.4.0inwl-terraform-wlplatform) cross upstream namingchanges that would rename live Azure resources.
~> 0.4ranges inwl-terraform-ittechwould be rewritten to~> 1.0rather thanpinned.
Those six blocks are migrated by hand.
Verified since this PR was opened: the fork's
maindoes not contain80c13e5"Enableuse of hyphen for API Management resources", so the APIM rename footgun is avoided; and
upstream
0.4.2→0.4.3is purely additive (1,611 insertions, 0 deletions), so the0.4.2pins get no name change from the version jump.
wl-ai carve-out
The second rule disables the replacement for
wl-ai/modules/**inwl-terraform-lab. Thoseinstances (
app,cdn,messaging,cache,bot) feedname_uniqueinto live storageaccounts, ServiceBus, managed Redis and a bot service; migrating them would force
destroy/recreate across ai-dev/stg/prod. Cost of the carve-out ≈$14/month. Each call site
should also get an inline comment so the exception is not silently "fixed" later.
Downstream impact
renovate-terraform-infra.jsonis the global config (RENOVATE_CONFIG_FILE) andforceClidefaults true, so this rule applies to every autodiscovered repo regardless of its own
renovate.json. The workflow triggers onpull_requesttouching this file and the reusableworkflow exposes no
dryRuninput, so pushing to this branch runs the sweep for real:expect replacement PRs in
wl-terraform-{infrastructure,ittech,lab,hrtech}(~39 blocks).#211 works around this by carrying
"dryRun": "full"in its first commit; do the same here.Expected plan shape on each consumer PR:
random_stringdestroys only, 0 creates, 0replacements. No
movedblocks needed — the module block name is unchanged.terraform-plan-diffwill go red on those PRs; it is a commit status, not a required check,and module replacements are not automerge-eligible, so each downstream PR needs human approval
plus code-owner review.
Remove this rule once the estate is migrated.