Skip to content

Waves and approvals

llms.txtlists every page for an agent
Optional: hand this page to your coding agentThe steps work by hand too.
Show the whole prompt
Read https://intentius.io/terragucci/tutorial/waves/.
In the terragucci clone with the example booted, run `just example change destroy` and read the plan note. Then stop and print the `just example merge destroy` and `just example approve` commands for me. Do not run either of them.
Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.

The apply is one job per wave, canary first.

Wave Roots
1 the dev platform root
2 the four dev services
3 the staging and prod platform roots
4 their eight services

With the default gate on-destructive a wave waits only when its plans destroy or replace something. This scenario makes one destroy.

$ just example change destroy
[example] pushed change/destroy at 56c5c84b
[example] run 8 for 56c5c84b (pull_request): success (http://localhost:3300/terragucci-admin/example/actions/runs/8/jobs/1/attempt/1)
[example] run 9 for 56c5c84b (push): success (http://localhost:3300/terragucci-admin/example/actions/runs/9/jobs/0/attempt/1)

  Pull request  http://localhost:3300/terragucci-admin/example/pulls/4 (the plan note is in its conversation)
  Plan          http://localhost:3300/terragucci-admin/example/actions/runs/8/jobs/1/attempt/1 (success)
  Check         http://localhost:3300/terragucci-admin/example/actions/runs/9/jobs/0/attempt/1 (success)

That pull request drops the records table of staging email. Its note names the destroy at the top:

The plan note on the destroy pull request in Forgejo: the records table of staging email named under destroys, and wave 4 waiting for an approval, with the terragucci approve command for its digestThe plan note on the destroy pull request in Forgejo: the records table of staging email named under destroys, and wave 4 waiting for an approval, with the terragucci approve command for its digest

The example runs approval: sealed, so its approvals need a key. Your own repo defaults to ledger, with no key:

approval Where An approval counts when
sealed the example, whose chant.workspace.json lists its wave gates it is sealed by a key listed in .chant/allowed_signers on the default branch as it was before the merge being applied
ledger your own repo, by default it approves the wave’s digest; no key needed

Approve a waiting wave shows both, and pr-review.

  1. Merge it with just example merge destroy, or in Forgejo signed in with the account just example up printed. That command’s first run also generates a key for the example’s sealed mode and commits it to .chant/allowed_signers on main; that file lists who may approve.

    $ just example merge destroy
    [example] listed the reader's key in .chant/allowed_signers
    [example] merged change/destroy into main
    
      Merged    pull request 4 into main
      Pipeline  http://localhost:3300/terragucci-admin/example/actions/runs/11/jobs/0/attempt/1 (failure)
        terragucci approve wave-4 --plan jcs1-sha256:284d6a4f3175db20ea6eb2e9a490ac387afaee4a1dc209077125cebe842f8b28 --sign
  2. Wave 4 plans the destroy and stops. Its job exits with code 3 and prints the approve command:

    Wave 4's apply job in Forgejo, stopped with exit code 3 and printing terragucci approve wave-4 with the plan's digestWave 4's apply job in Forgejo, stopped with exit code 3 and printing terragucci approve wave-4 with the plan's digest
  3. Read the wave’s plans in the report. The terragucci approve command carries the digest the wave planned, so the approval covers those plans and no others.

  4. Approve with the example’s generated key:

    Terminal window
    just example approve

    It runs terragucci approve wave-4 with that key.

  5. Run the wave’s job again, and wave 4 applies. A plan that changes afterwards is not covered, as the next page shows.

To make every wave wait, set gate: always in terragucci.yml.

Tutorial step 4 of 11.

terragucci

These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.