Add init-time policy evaluation#38519
Draft
dsa0x wants to merge 8 commits into
Draft
Conversation
Contributor
Changelog WarningCurrently this PR would target a v1.16 release. Please add a changelog entry for in the .changes/v1.16 folder, or discuss which release you'd like to target with your reviewer. If you believe this change does not need a changelog entry, please add the 'no-changelog-needed' label. |
3b37dea to
20ce6af
Compare
943bd66 to
49366dd
Compare
20ce6af to
0cd9be4
Compare
49366dd to
93f20ff
Compare
0cd9be4 to
a60d49a
Compare
This was referenced May 5, 2026
93f20ff to
33b149a
Compare
a60d49a to
01c69f8
Compare
33b149a to
11ca31f
Compare
01c69f8 to
1bbda0b
Compare
6a83b13 to
bf0f7d9
Compare
ceca9d8 to
f6cce9a
Compare
bf0f7d9 to
38b1a14
Compare
SarahFrench
reviewed
May 29, 2026
Member
SarahFrench
left a comment
There was a problem hiding this comment.
I jumped ahead a bit. but I took a glance at this PR and realised I could give some feedback that might be useful if you're blocked while other PRs are under review.
To be explicit, I'm planning to continue focusing on the earliest PR that's open for review out of the stack, so I may not follow up here again until we reach this PR's review.
38b1a14 to
a9e8fca
Compare
f6cce9a to
abe1c41
Compare
f144183 to
af50d84
Compare
fcb3f12 to
6c5df78
Compare
27f16d4 to
a11fa35
Compare
6c5df78 to
556920d
Compare
a11fa35 to
7dd9e87
Compare
137d602 to
cc2ed92
Compare
8b6d17f to
de767e7
Compare
cc2ed92 to
1b55da5
Compare
e0cdbb3 to
4405313
Compare
772e969 to
30cd8da
Compare
d7066be to
d192685
Compare
30cd8da to
3d0811b
Compare
3d0811b to
7155955
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is part of a stacked series to upstream the policy work in smaller, reviewable pieces:
This PR adds policy evaluation during
terraform init. That includes evaluating policy during module installation and provider installation, wiring the init flow through the policy client, and adding the init-specific view/test support needed to surface policy outcomes correctly in that stage of execution.Contrary to the plan/apply workflow, policy failures during init would result in a non-zero exit of the terraform command.
Included here
initwdhook changes needed to support policy checks during module installationTarget Release
1.16.x
Rollback Plan
Changes to Security Controls
Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.
CHANGELOG entry