Skip to content

Dry-run terraform Renovate sweeps on PR, and migrate enterprise modules to the naming fork (FENG-2988) - #211

Merged
Martin Charbonneau (mcharbo) merged 3 commits into
mainfrom
feature/FENG-2988
Sep 11, 2026
Merged

Martin Charbonneau (mcharbo) merged 3 commits into
mainfrom
feature/FENG-2988

Conversation

@mcharbo

@mcharbo Martin Charbonneau (mcharbo) commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Jira issue link: FENG-2988

Two changes: a CI guard that makes these sweeps reviewable, and the naming-fork migration
rule that motivated needing one.

1. ci: dry-run the terraform Renovate sweeps on pull_request

renovate-terraform.yml and renovate-terraform-infra.yml trigger on any pull_request
touching their config, and reusable-renovate-workflow.yml checks out the PR branch's
config (actions/checkout with no ref) then runs Renovate with an org-wide PAT and
autodiscover: true. There is no environment gate and no dryRun input.

So a config PR opens real PRs in every matched repo the moment it is pushed. Merging is
bookkeeping; the PR event is the deploy. That is a sharp edge for a shared config repo.

renovate.yml already guards against exactly this — on pull_request it narrows
autodiscover to a single repo, commented "prevent triggering hundreds of pipelines in other
repos."
This generalises that as a dry_run input, so the terraform sweeps get the same
protection while still logging what they would do across the whole estate.

  • reusable-renovate-workflow.yml: new dry_run boolean input (default false), exporting
    RENOVATE_DRY_RUN=full. Set via GITHUB_ENV in a conditional step rather than the env:
    block, because Renovate rejects an empty RENOVATE_DRY_RUN — the variable has to be absent,
    not blank.
  • Both terraform callers: dry_run: ${{ github.event_name == 'pull_request' }}.

renovate.yml is left alone; its single-repo filter already covers it.

2. feat: migrate enterprise modules to the Workleap naming fork

A packageRules replacement entry in renovate-terraform.json migrating
Azure/naming/azurerm → app.terraform.io/Workleap/naming/azurerm 1.0.1 across the
autodiscovered workleap/terraform-*-enterprise-* repos.

Why

Azure/naming/azurerm declares two unconditional random_string resources per module
instance. Only the name_unique outputs consume them, so for nearly every consumer they are
inert — but HCP Terraform bills $0.47/month per managed resource. Enumeration of all 455
workspaces found 4,470 random_* of 27,110 billable (16.5%), ≈$2,101/month ≈ $25,200/year,
~4,300 of which come from this module.

FENG-2646 published the fork, ran a pilot consumer bump (workleap/wl-terraform-hrtech#946)
and closed. The rule meant to drive the rollout — #207 — has been open and unmerged since
2026-08-05, so nothing in the estate consumes the fork.

Why enterprise repos, and why this file rather than #207

FENG-2646 measured direct consumer call sites at only ~8–15% of the spend; the rest sits in
the nested enterprise-* copies. #207 targets renovate-terraform-infra.json
(wl-terraform-*), i.e. the small half. Each enterprise module bump cuts a new module version
that reaches consumers through existing Renovate anyway, so leaf-first is both higher-yield and
less churn — and it is the ordering FENG-2646 specified.

terraform-*-vertical-* is deliberately not included yet; it follows in a second PR once
the enterprise leaves are merged and re-tagged.

Scoping

matchCurrentValue is /^0\.4\.[23]$/:

  • The fork is cut from upstream tag 0.4.3 (a837381). Verified the fork's main does not
    contain 80c13e5 "Enable use of hyphen for API Management resources", which would rename
    live APIM instances in sgm-{dev,stg,prod}-config-api.
  • Upstream 0.4.2 → 0.4.3 is purely additive (git diff --stat 75d5afa a837381: 1,611
    insertions, 0 deletions), so the 0.4.2 pins get no name change from the version jump.

replacementVersion is 1.0.1, not the 1.0.0 in #207. 1.0.0 is the superseded sha256-seed
build; 1.0.1 is the opt-in unique-random-string model and the only version whose
tests/name_unique.tftest.hcl runs green in CI.

Dry-run evidence

Ran against the real estate before the guard existed, via a config-level "dryRun": "full"
(since removed —
log, results in
this comment):

30 repos would get a renovate/azure-naming-azurerm-replacement branch, all
enterprise-*, zero vertical-*. No package-lookup failure for the private registry module.

Worth noting: 30, not the 18 a gh search code sweep turned up — it missed aks,
storage-account, redis, postgresql, defender, monitor, monitor-vm,
eventgrid-topic, eventhub-namespace, auditing, cognitive-account,
application-gateway, web-app-windows and product-foundation. Confirms FENG-2646's warning
that code search is not exhaustive.

How to land it

PR runs are now dry by construction, so merging this is safe on its own. Fan out deliberately
afterwards via workflow_dispatch on Renovate Terraform Enterprise, or let the nightly
cron pick it up.

Expected shape of each downstream PR

terraform plan shows random_string destroys only — 0 creates, 0 replacements, and no
moved blocks (the module "azure_naming" block name is unchanged). Read that as "no
azurerm_* create or replace", not "no azurerm_* lines" — the FENG-2646 pilot confirmed
pre-existing drift muddies the diff. Any other destroy is a stop signal.

Per-repo gate before merge: grep -rn "name_unique\|unique-seed" must be clean.

terraform-plan-diff will go red on the downstream PRs; it is a commit status, not a required
check. Replacements are not automerge-eligible, so each needs human plus code-owner review.

Known, not introduced here

WARN: Post-upgrade task did not match any on allowedCommands list fires on every replacement
branch, so terraform-docs will not regenerate on those PRs. Pre-existing — it fires
identically on the existing renovate/terraform-provider-minor-patch branches.

Follow-ups

Dry run for now: the workflow has no dryRun input and triggers on every
pull_request touching this file, so the first push would otherwise open the
downstream replacement PRs before anyone has read the sweep. Removed in a
follow-up commit on this branch once the log is reviewed.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The documented dry-run log is not currently published for reviewer inspection.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Configures a staged Renovate migration of enterprise Terraform modules to Workleap’s naming fork.

Changes:

  • Enables full Renovate dry-run mode.
  • Adds a scoped replacement to Workleap naming 1.0.1 for enterprise repositories.
File summaries
File Description
renovate-terraform.json Configures the dry run and enterprise naming-module replacement.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread renovate-terraform.json Outdated
@mcharbo

Copy link
Copy Markdown
Contributor Author

Dry-run results

renovate-terraform-enterprise ran 13m against the real estate with "dryRun": "full"
(run). All checks green.

30 repos would get a renovate/azure-naming-azurerm-replacement branch, all enterprise-*, zero vertical-* — the matchRepositories scoping holds.

The 30 repos
terraform-azurerm-enterprise-acr                                    terraform-azurerm-enterprise-monitor
terraform-azurerm-enterprise-aks                                    terraform-azurerm-enterprise-monitor-vm
terraform-azurerm-enterprise-api-management                         terraform-azurerm-enterprise-nsg
terraform-azurerm-enterprise-app-configuration                      terraform-azurerm-enterprise-postgresql
terraform-azurerm-enterprise-app-insight                            terraform-azurerm-enterprise-public-ip
terraform-azurerm-enterprise-app-service-plan                       terraform-azurerm-enterprise-redis
terraform-azurerm-enterprise-application-gateway                    terraform-azurerm-enterprise-resource-group
terraform-azurerm-enterprise-auditing                               terraform-azurerm-enterprise-static-web-site
terraform-azurerm-enterprise-cdn                                    terraform-azurerm-enterprise-storage-account
terraform-azurerm-enterprise-cognitive-account                      terraform-azurerm-enterprise-vnet
terraform-azurerm-enterprise-defender                               terraform-azurerm-enterprise-web-app-windows
terraform-azurerm-enterprise-eventgrid-namespace-event-queue-sub    terraform-workleap-enterprise-product-foundation
terraform-azurerm-enterprise-eventgrid-topic
terraform-azurerm-enterprise-eventhub-namespace
terraform-azurerm-enterprise-function
terraform-azurerm-enterprise-keyvault
terraform-azurerm-enterprise-log-analytics
terraform-azurerm-enterprise-machine-learning-workspace

Notable: 30, not the 18 that gh search code turned up. The code search missed aks,
storage-account, redis, postgresql, defender, monitor, monitor-vm,
eventgrid-topic, eventhub-namespace, auditing, cognitive-account,
application-gateway, web-app-windows and product-foundation. Confirms FENG-2646's
warning that code search is not exhaustive — treat any hand-built inventory as a floor.

Registry resolution

No package-lookup failure for app.terraform.io/Workleap/naming/azurerm; Renovate resolved
the private registry and the 1.0.1 target fine. The only Package lookup failures in the
log are unrelated (goldilocks, keda in vertical-kubernetes).

Two things worth a decision before the real run

  1. terraform-workleap-enterprise-product-foundation is included. It matches
    terraform-*-enterprise-*, but FENG-2646 ordered it after the verticals, since it is a
    composite that consumes the other enterprise modules. Its own direct naming block is
    independent of its children, so swapping it now is harmless — but if we want to honour the
    stated ordering it is a one-line matchRepositories exclusion.
  2. WARN: Post-upgrade task did not match any on allowedCommands list fires on every
    replacement branch, so terraform-docs will not regenerate on these PRs. Pre-existing —
    it fires identically on the existing renovate/terraform-provider-minor-patch branches —
    so not introduced here, but it means README docs blocks stay stale until something else
    regenerates them.

Also seen: a pre-existing grouped renovate/terraform-module-minor-patch branch already
touches Azure/naming/azurerm in most of these repos (0.4.2 → 0.4.3). The replacement
supersedes it; expect those grouped PRs to drop the naming entry once this lands.

@mcharbo Martin Charbonneau (mcharbo) changed the title Migrate enterprise modules to the Workleap naming fork (FENG-2988) Dry-run terraform Renovate sweeps on PR, and migrate enterprise modules to the naming fork (FENG-2988) Sep 11, 2026
These workflows run Renovate against the whole autodiscovered estate using the
config from the PR branch, with an org-wide PAT. A config PR therefore opened
real PRs in every matched repo before anyone could review the change - merging
was bookkeeping, the PR event was the deploy.

renovate.yml already guards against this by narrowing autodiscover to a single
repo on pull_request; this generalises that as a dry_run input so the terraform
sweeps get the same protection without losing estate-wide coverage of the log.

Replaces the config-level "dryRun" that this branch used as a stopgap.
Comment thread renovate-terraform.json Outdated
…description

Addresses review on #211: the dry-run log was only readable from the raw job
output, and the packageRules description read as generated prose.
@mcharbo

Martin Charbonneau (mcharbo) commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor Author

Follow-up filed: FENG-2995 — move the Renovate runner and global configs out of this repo into wl-github-actions.

Deliberately not bundled here. The move needs a keyvault RBAC verification (and possibly a wl-terraform-infrastructure change) for the wl-github-actions identity to read renovate-github-pat / renovate-tfc-token / renovate-ado-feed-pat, and stalling this PR behind that delays the savings. The replacement packageRules travel with the files whenever the move happens.

One finding from this PR's dry run is captured there as a work item: renovate.json in this repo doubles as both the repo's own config and the preset the two terraform sweeps extend, so the sweeps inherit an allowedCommands regex written for this repo's terraform-docs call. That is the direct cause of the Post-upgrade task did not match any on allowedCommands list warning on all 30 replacement branches — terraform-docs silently does not regenerate on Renovate PRs. Pre-existing, not introduced here.

@mcharbo
Martin Charbonneau (mcharbo) merged commit cc01185 into main Sep 11, 2026
8 checks passed
@mcharbo
Martin Charbonneau (mcharbo) deleted the feature/FENG-2988 branch September 11, 2026 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants