Skip to content

Your first pull request

llms.txtlists every page for an agent
Optional: hand this page to your coding agentThe steps work by hand too.
Show the whole prompt
Read https://intentius.io/terragucci/tutorial/first-pull-request/.
In the terragucci clone with the example booted, run the `just example` commands on the page. Summarize what the plan note and the failed check say, and where they differ from the page.
Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.

Orders in dev should keep unpicked jobs for seven days instead of four: one line in envs/dev/orders/main.tf.

  1. One command makes the branch and opens the pull request. The push and the pull request each start a run: the pull request’s run posts the plan note, the push’s run is the check. The output prints both run numbers.

    $ just example change one-root
    [example] pushed change/one-root at 9f2c4651
    [example] run 2 for 9f2c4651 (pull_request): success (http://localhost:3300/terragucci-admin/example/actions/runs/2/jobs/1/attempt/1)
    [example] run 3 for 9f2c4651 (push): success (http://localhost:3300/terragucci-admin/example/actions/runs/3/jobs/0/attempt/1)
    
      Pull request  http://localhost:3300/terragucci-admin/example/pulls/1 (the plan note is in its conversation)
      Plan          http://localhost:3300/terragucci-admin/example/actions/runs/2/jobs/1/attempt/1 (success)
      Check         http://localhost:3300/terragucci-admin/example/actions/runs/3/jobs/0/attempt/1 (success)
  2. Open the pull request link in Forgejo:

    The pull request's files tab, adding job_retention_seconds = 604800 to dev ordersThe pull request's files tab, adding job_retention_seconds = 604800 to dev orders
  3. Look at the push’s run, the second link printed. tf-check runs on the branch push, and on a pull request only from a fork: a format check, then validate for every root. Both steps pass. The plan note is a comment in the conversation:

    The plan note on a Forgejo pull request for a change to one root: one instance in one group, no destroys, wave 2 with its set digest, and the change to the jobs queue, which keeps messages for seven daysThe plan note on a Forgejo pull request for a change to one root: one instance in one group, no destroys, wave 2 with its set digest, and the change to the jobs queue, which keeps messages for seven days
  1. Add a badly formatted file:

    locals {
    team = "orders"
    owner = "shop"
    }
  2. The scenario opens it as a second pull request. The check fails, and just example logs prints the file and the change tofu fmt would make.

    $ just example change unformatted
    [example] pushed change/unformatted at 5fe05168
    [example] run 4 for 5fe05168 (pull_request): success (http://localhost:3300/terragucci-admin/example/actions/runs/4/jobs/1/attempt/1)
    [example] run 5 for 5fe05168 (push): failure (http://localhost:3300/terragucci-admin/example/actions/runs/5/jobs/0/attempt/1)
    
      Pull request  http://localhost:3300/terragucci-admin/example/pulls/2 (the plan note is in its conversation)
      Plan          http://localhost:3300/terragucci-admin/example/actions/runs/4/jobs/1/attempt/1 (success)
      Check         http://localhost:3300/terragucci-admin/example/actions/runs/5/jobs/0/attempt/1 (failure)
    $ just example logs
    envs/dev/orders/locals.tf
    --- old/envs/dev/orders/locals.tf
    +++ new/envs/dev/orders/locals.tf
    @@ -1,4 +1,4 @@
     locals {
    -    team   = "orders"
    +  team  = "orders"
       owner = "shop"
     }
  3. In Forgejo the failed step is “Format check and validate, every root”:

    The failed check job in Forgejo, its format step open on the diff tofu fmt -check printed for envs/dev/orders/locals.tfThe failed check job in Forgejo, its format step open on the diff tofu fmt -check printed for envs/dev/orders/locals.tf
  4. Run tofu fmt -recursive in your own repo and the check goes green again.

Every push runs the check stage on every root. It needs no cloud credentials, because it never plans.

Tutorial step 2 of 11.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.