Terraform Run Triggers are a way to connect a child workspace to one or more source (root) workspaces. Run Triggers allow runs to queue automatically in your child workspace(s) on successful apply of runs in any of the source workspaces.
This example repo aims to simulate Run Triggers in an Azure environment.
source-workspace
creates an Azure Service Principal for authentication and outputs details- Outputs are marked as 'sensitive' to prevent plaintext storage in Terraform state
child-workspace
calls this newly created SP via the Remote State Data Source, authenticates to Azure, and creates resources (a simple resource group)
- This example can be modified to provision multiple SPs using for_each for multi-tenant deployments.
- The SP created by
source-workspace
must have specific permissions (you can use 'Owner' for testing purposes)- Contributor and one of the following sets:
- AppRoleAssignment.ReadWrite.All and Application.Read.All; or
- AppRoleAssignment.ReadWrite.All and Directory.Read.All; or
- Application.ReadWrite.All; or
- Directory.ReadWrite.All
- Contributor and one of the following sets:
- Clone or fork this repo
- Set org name in backend.tf in each workspace directory and in remote_state.tf in
child-workspace
- Commit changes (if using Version Control workflow) or save changes (if using CLI-driven workflow)
- Create two workspaces in TFC/E:
- az-srcwksp
- az-chwksp
- If using VC workflow, be sure to specify the path for each workspace
- Ex. /source-workspace/ for az-srcwksp
- Add 'src-wksp' to 'ch-wksp' as a source workspace via instructions here
- Authenticate to Azure
- Perform a successful run on the source workspace
- once complete, a plan will automatically run on the child workspace