(we use gitlab-ci's built-in review process for approval).
At the end of the day, approval's still a human job, and humans make mistakes. Right? :D
Terraform is an incredibly powerful tool, and you can make some monumentally huge mistakes with it.
- plan against staging
- get a PR approval
- apply against staging
- plan against prod
- apply against prod
- merge
Being forced to plan (and get someone up review said plan) before applying makes it far, far less likely you’ll do the level of damage described in this blog post.
The best strategy is to have a repository for your modules only so you can specify the version[0] you want to use, and separate environments by folders.
[0]: https://www.terraform.io/docs/language/modules/sources.html#...
That said, Terraform breaks so often that if we did it all automated, we'd have a million more Git commits from trying to fix broken apply's.