Repository navigation
Dry-run terraform Renovate sweeps on PR, and migrate enterprise modules to the naming fork (FENG-2988) - #211
Conversation
Dry run for now: the workflow has no dryRun input and triggers on every pull_request touching this file, so the first push would otherwise open the downstream replacement PRs before anyone has read the sweep. Removed in a follow-up commit on this branch once the log is reviewed.
There was a problem hiding this comment.
🟡 Changes recommended
The documented dry-run log is not currently published for reviewer inspection.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Configures a staged Renovate migration of enterprise Terraform modules to Workleap’s naming fork.
Changes:
- Enables full Renovate dry-run mode.
- Adds a scoped replacement to Workleap naming
1.0.1for enterprise repositories.
File summaries
| File | Description |
|---|---|
renovate-terraform.json |
Configures the dry run and enterprise naming-module replacement. |
Review details
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Dry-run results
30 repos would get a The 30 reposNotable: 30, not the 18 that Registry resolutionNo package-lookup failure for Two things worth a decision before the real run
Also seen: a pre-existing grouped |
These workflows run Renovate against the whole autodiscovered estate using the config from the PR branch, with an org-wide PAT. A config PR therefore opened real PRs in every matched repo before anyone could review the change - merging was bookkeeping, the PR event was the deploy. renovate.yml already guards against this by narrowing autodiscover to a single repo on pull_request; this generalises that as a dry_run input so the terraform sweeps get the same protection without losing estate-wide coverage of the log. Replaces the config-level "dryRun" that this branch used as a stopgap.
de50f3e to
fc26325
Compare
…description Addresses review on #211: the dry-run log was only readable from the raw job output, and the packageRules description read as generated prose.
|
Follow-up filed: FENG-2995 — move the Renovate runner and global configs out of this repo into Deliberately not bundled here. The move needs a keyvault RBAC verification (and possibly a One finding from this PR's dry run is captured there as a work item: |
Jira issue link: FENG-2988
Two changes: a CI guard that makes these sweeps reviewable, and the naming-fork migration
rule that motivated needing one.
1.
ci:dry-run the terraform Renovate sweeps onpull_requestrenovate-terraform.ymlandrenovate-terraform-infra.ymltrigger on anypull_requesttouching their config, and
reusable-renovate-workflow.ymlchecks out the PR branch'sconfig (
actions/checkoutwith noref) then runs Renovate with an org-wide PAT andautodiscover: true. There is no environment gate and nodryRuninput.So a config PR opens real PRs in every matched repo the moment it is pushed. Merging is
bookkeeping; the PR event is the deploy. That is a sharp edge for a shared config repo.
renovate.ymlalready guards against exactly this — onpull_requestit narrowsautodiscover to a single repo, commented "prevent triggering hundreds of pipelines in other
repos." This generalises that as a
dry_runinput, so the terraform sweeps get the sameprotection while still logging what they would do across the whole estate.
reusable-renovate-workflow.yml: newdry_runboolean input (defaultfalse), exportingRENOVATE_DRY_RUN=full. Set viaGITHUB_ENVin a conditional step rather than theenv:block, because Renovate rejects an empty
RENOVATE_DRY_RUN— the variable has to be absent,not blank.
dry_run: ${{ github.event_name == 'pull_request' }}.renovate.ymlis left alone; its single-repo filter already covers it.2.
feat:migrate enterprise modules to the Workleap naming forkA
packageRulesreplacement entry inrenovate-terraform.jsonmigratingAzure/naming/azurerm→app.terraform.io/Workleap/naming/azurerm1.0.1across theautodiscovered
workleap/terraform-*-enterprise-*repos.Why
Azure/naming/azurermdeclares two unconditionalrandom_stringresources per moduleinstance. Only the
name_uniqueoutputs consume them, so for nearly every consumer they areinert — but HCP Terraform bills $0.47/month per managed resource. Enumeration of all 455
workspaces found 4,470
random_*of 27,110 billable (16.5%), ≈$2,101/month ≈ $25,200/year,~4,300 of which come from this module.
FENG-2646 published the fork, ran a pilot consumer bump (
workleap/wl-terraform-hrtech#946)and closed. The rule meant to drive the rollout — #207 — has been open and unmerged since
2026-08-05, so nothing in the estate consumes the fork.
Why enterprise repos, and why this file rather than #207
FENG-2646 measured direct consumer call sites at only ~8–15% of the spend; the rest sits in
the nested
enterprise-*copies. #207 targetsrenovate-terraform-infra.json(
wl-terraform-*), i.e. the small half. Each enterprise module bump cuts a new module versionthat reaches consumers through existing Renovate anyway, so leaf-first is both higher-yield and
less churn — and it is the ordering FENG-2646 specified.
terraform-*-vertical-*is deliberately not included yet; it follows in a second PR oncethe enterprise leaves are merged and re-tagged.
Scoping
matchCurrentValueis/^0\.4\.[23]$/:0.4.3(a837381). Verified the fork'smaindoes notcontain
80c13e5"Enable use of hyphen for API Management resources", which would renamelive APIM instances in
sgm-{dev,stg,prod}-config-api.0.4.2→0.4.3is purely additive (git diff --stat 75d5afa a837381: 1,611insertions, 0 deletions), so the
0.4.2pins get no name change from the version jump.replacementVersionis1.0.1, not the1.0.0in #207.1.0.0is the superseded sha256-seedbuild;
1.0.1is the opt-inunique-random-stringmodel and the only version whosetests/name_unique.tftest.hclruns green in CI.Dry-run evidence
Ran against the real estate before the guard existed, via a config-level
"dryRun": "full"(since removed —
log, results in
this comment):
30 repos would get a
renovate/azure-naming-azurerm-replacementbranch, allenterprise-*, zerovertical-*. No package-lookup failure for the private registry module.Worth noting: 30, not the 18 a
gh search codesweep turned up — it missedaks,storage-account,redis,postgresql,defender,monitor,monitor-vm,eventgrid-topic,eventhub-namespace,auditing,cognitive-account,application-gateway,web-app-windowsandproduct-foundation. Confirms FENG-2646's warningthat code search is not exhaustive.
How to land it
PR runs are now dry by construction, so merging this is safe on its own. Fan out deliberately
afterwards via
workflow_dispatchon Renovate Terraform Enterprise, or let the nightlycron pick it up.
Expected shape of each downstream PR
terraform planshowsrandom_stringdestroys only — 0 creates, 0 replacements, and nomovedblocks (themodule "azure_naming"block name is unchanged). Read that as "noazurerm_*create or replace", not "noazurerm_*lines" — the FENG-2646 pilot confirmedpre-existing drift muddies the diff. Any other destroy is a stop signal.
Per-repo gate before merge:
grep -rn "name_unique\|unique-seed"must be clean.terraform-plan-diffwill go red on the downstream PRs; it is a commit status, not a requiredcheck. Replacements are not automerge-eligible, so each needs human plus code-owner review.
Known, not introduced here
WARN: Post-upgrade task did not match any on allowedCommands listfires on every replacementbranch, so
terraform-docswill not regenerate on those PRs. Pre-existing — it firesidentically on the existing
renovate/terraform-provider-minor-patchbranches.Follow-ups
matchRepositoriestoterraform-*-vertical-*.replacementVersioncorrected to1.0.1and its body refreshed. Itswl-ai carve-out rule is already correct and stays.