This repository contains a collection of GitHub Actions workflow templates that can be used with various types of repositories to automate the build, test, and deployment of applications and infrastructure.
The AWS Terraform workflows (plan & apply, module validation, destroy and drift) support both Terraform and OpenTofu through the enable-opentofu input. This allows you to use OpenTofu as a drop-in replacement for Terraform while keeping the same workflow functionality.
with:
enable-opentofu: true # Use OpenTofu instead of TerraformPlease refer to the following documentation for more information on the workflows:
- Terraform Plan & Apply (AWS) - Automated Terraform deployment pipeline for AWS
- Terraform Plan & Apply (Azure) - Input-driven plan, review & apply pipeline for Azure
- Terraform Module Validation - Validate Terraform modules
- Terraform Module Release - Release and publish Terraform modules
- Terraform Destroy (AWS) - Safely destroy Terraform-managed infrastructure
- Terraform Destroy (Azure) - Guarded, input-driven teardown for Azure
- Terraform Drift Detection - Detect configuration drift in deployed infrastructure
- Terraform Drift Detection (Azure) - Scheduled drift detection for Azure (issue + optional Slack)
- Terragrunt Plan & Apply (AWS) - Automated Terragrunt deployment pipeline for AWS (optional per-unit matrix for plan and apply on
main) - Terragrunt Manual Dispatch - Manually trigger Terragrunt operations
- Helm Chart Validation - Lint, template and schema-validate Helm charts
- Helm Chart Release - Package and publish Helm charts
- Docker Build, Push & Security Scan - Build, scan, and push Docker images
- GitHub Workflow Validation - Validate GitHub Actions workflow files
- Template Update - Keep repository files in sync with templates
The Terragrunt workflow can run in matrix mode (enable-matrix: true), with one job per Terragrunt unit for plan and apply. That keeps large estates fast, but splits the plan across many jobs. To keep the change reviewable, the per-unit plans are aggregated into a single plan summary: totals, a table of changed units per account and region, a list of every resource to be destroyed or replaced, and the trimmed plan for each unit with the refresh output removed. The summary is posted to the pull request, the workflow run's job summary and the job log, so scheduled and manually dispatched plans get it too.
The summary is built by two composite actions, terragrunt-plan-collect (per unit) and terragrunt-plan-summary (aggregation). See Plan Summary for details.
The workflows are built from composite actions in .github/actions, which can also be used directly in your own workflows (uses: appvia/appvia-cicd-workflows/.github/actions/<action-name>@<ref>). See Composite Actions for the inputs, outputs and examples of each.
- Shared: cicd-config - Copies centralised configuration (e.g.
.tflint.hcl) into the workspace; schema-validate - Validates YAML or JSON files against a JSON Schema - Terraform: terraform-bootstrap, terraform-bootstrap-noauth - Install Terraform or OpenTofu, authenticate with AWS and run
init; terraform-plan-encrypt, terraform-plan-decrypt - Encrypt and decrypt plan artifacts - Terragrunt: terragrunt-bootstrap, terragrunt-bootstrap-unauth - Install Terraform and Terragrunt and authenticate with AWS; terragrunt-diff - Diff rendered inputs against
main; terragrunt-matrix - Build the per-unit job matrix; terragrunt-plan-collect, terragrunt-plan-summary - Aggregate matrix plans into one summary; terragrunt-pr - Post the review status comment - Kubernetes: kubernetes-platform-promotion - Validate that environment promotions never regress versions
- Template: template-update - Sync an allowlist of files from a template repository via pull request; template-update-azure - Sync a whole template repository except an exclusion list
Before raising a pull request, run the same checks CI runs, locally:
make validateRun make help to see all available targets (individual linters, the SHA-pinning audit, and other helper scripts). Requires actionlint, yamllint, shellcheck, and Node.js (npx) to be installed locally, e.g. via brew install actionlint yamllint shellcheck node. You can also use the reusable GitHub Workflow Validation workflow in CI.
Centralised configuration (config/) and helper scripts (scripts/) ship with the composite actions in this repository, rather than being downloaded from raw.githubusercontent.com, so nothing here depends on this repository being public. Calling repositories do need permission to resolve the workflows and actions: under Settings → Actions → General → Access, set this repository to be accessible from repositories in the organisation. See Private repository access for detail.
The workflow templates in this repository are designed to be used with GitHub's deployment protection and approval feature. This feature allows you to require manual approval before a deployment can be executed. When merging to main branch we automatically use a 'production' environment, this can be configured with the repository setting to ensure all changes to this environment must be manually approved before applying the change.
- Go to the repository settings
- Click on the
Branchestab - Click on the
Add rulebutton - In the
Branch name patternfield, enter the branch name you want to protect (e.g.main) - Check the
Require pull request reviews before mergingcheckbox - Check the
Require status checks to pass before mergingcheckbox - Check the
Require branches to be up to date before mergingcheckbox - Check the
Include administratorscheckbox - Click on
Environmentsand choose the environment you want to protect (e.g.production) - Check the
Require reviewerscheckbox and select the reviewers you want to require approval from - Check the
Prevent self-reviewcheckbox
This project is distributed under the Apache License, Version 2.0.