Waves and approvals
Optional: hand this page to your coding agentThe steps work by hand too.Show the whole prompt
Read https://intentius.io/terragucci/tutorial/waves/.
In the terragucci clone with the example booted, run `just example change destroy` and read the plan note. Then stop and print the `just example merge destroy` and `just example approve` commands for me. Do not run either of them.
Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.The apply is one job per wave, canary first.
| Wave | Roots |
|---|---|
| 1 | the dev platform root |
| 2 | the four dev services |
| 3 | the staging and prod platform roots |
| 4 | their eight services |
With the default gate on-destructive a wave waits only when its plans destroy or replace something. This scenario makes one destroy.
$ just example change destroy
[example] pushed change/destroy at 56c5c84b
[example] run 8 for 56c5c84b (pull_request): success (http://localhost:3300/terragucci-admin/example/actions/runs/8/jobs/1/attempt/1)
[example] run 9 for 56c5c84b (push): success (http://localhost:3300/terragucci-admin/example/actions/runs/9/jobs/0/attempt/1)
Pull request http://localhost:3300/terragucci-admin/example/pulls/4 (the plan note is in its conversation)
Plan http://localhost:3300/terragucci-admin/example/actions/runs/8/jobs/1/attempt/1 (success)
Check http://localhost:3300/terragucci-admin/example/actions/runs/9/jobs/0/attempt/1 (success)That pull request drops the records table of staging email. Its note names the destroy at the top:


The example runs approval: sealed, so its approvals need a key. Your own repo defaults to ledger, with no key:
approval |
Where | An approval counts when |
|---|---|---|
sealed |
the example, whose chant.workspace.json lists its wave gates |
it is sealed by a key listed in .chant/allowed_signers on the default branch as it was before the merge being applied |
ledger |
your own repo, by default | it approves the wave’s digest; no key needed |
Approve a waiting wave shows both, and pr-review.
-
Merge it with
just example merge destroy, or in Forgejo signed in with the accountjust example upprinted. That command’s first run also generates a key for the example’s sealed mode and commits it to.chant/allowed_signerson main; that file lists who may approve.$ just example merge destroy [example] listed the reader's key in .chant/allowed_signers [example] merged change/destroy into main Merged pull request 4 into main Pipeline http://localhost:3300/terragucci-admin/example/actions/runs/11/jobs/0/attempt/1 (failure) terragucci approve wave-4 --plan jcs1-sha256:284d6a4f3175db20ea6eb2e9a490ac387afaee4a1dc209077125cebe842f8b28 --sign -
Wave 4 plans the destroy and stops. Its job exits with code 3 and prints the approve command:


-
Read the wave’s plans in the report. The
terragucci approvecommand carries the digest the wave planned, so the approval covers those plans and no others. -
Approve with the example’s generated key:
Terminal window just example approveIt runs
terragucci approve wave-4with that key. -
Run the wave’s job again, and wave 4 applies. A plan that changes afterwards is not covered, as the next page shows.
To make every wave wait, set gate: always in terragucci.yml.
Tutorial step 4 of 11.
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.