Skip to content

Example: COAT tag validation action integration#42383

Draft
Lev Gorbunov (levgorbunov1) wants to merge 10 commits into
mainfrom
integrate-coat-tag-validator
Draft

Example: COAT tag validation action integration#42383
Lev Gorbunov (levgorbunov1) wants to merge 10 commits into
mainfrom
integrate-coat-tag-validator

Conversation

@levgorbunov1

@levgorbunov1 Lev Gorbunov (levgorbunov1) commented May 11, 2026

Copy link
Copy Markdown
Contributor

@levgorbunov1 Lev Gorbunov (levgorbunov1) requested a review from a team as a code owner May 11, 2026 12:32
@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 1 to be updated, 0 to be replaced and 32 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! module.rds.aws_db_parameter_group.custom_parameters

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@levgorbunov1 Lev Gorbunov (levgorbunov1) changed the title Add coat tag validator workflow Example: COAT tag validation action integration May 11, 2026
@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

@levgorbunov1 Lev Gorbunov (levgorbunov1) marked this pull request as draft May 11, 2026 13:27
@sablumiah

Copy link
Copy Markdown
Contributor

Terraform Plan Summary

Terraform Plan: 2 to be created, 0 to be destroyed, 10 to be updated, 0 to be replaced and 23 unchanged.

Resources to create:

+ module.ecr-repo.github_actions_secret.ecr_registry_url["github-community"]
+ module.serviceaccount.github_actions_secret.cluster-name["github-community"]

Resources to update:

! aws_route53_zone.route53_zone
! module.ecr-repo.aws_ecr_repository.repo
! module.ecr-repo.aws_iam_policy.ecr[0]
! module.ecr-repo.aws_iam_role.github[0]
! module.irsa.module.iam_assumable_role.aws_iam_role.this[0]
! module.rds.aws_db_instance.rds
! module.rds.aws_db_parameter_group.custom_parameters
! module.rds.aws_db_subnet_group.db_subnet[0]
! module.rds.aws_iam_policy.irsa[0]
! module.rds.aws_kms_key.kms[0]

@sablumiah

Copy link
Copy Markdown
Contributor

This PR CANNOT be auto approved and requires manual approval from the Cloud Platform team.
Reason:
🕵️‍♂️ Manual review required: OPA auto approve policy checks did not pass.

Test Passed? Reason
allowlist This PR includes changes to modules / resources which are not on the allowlist, so we can't auto approve these changes. Please request a Cloud Platform team member's review in #ask-cloud-platform
ecr Valid ECR related terraform changes
hmpps-template Valid hmpps template related terraform changes
irsa Valid irsa related terraform changes
kubernetes_secret Valid K8s secret related terraform changes
rds Valid RDS module related terraform changes
secrets_manager Valid secrets manager related terraform changes
service_pod Valid Service pod related changes
sns Valid sns related terraform changes

Please raise it in #ask-cloud-platform Slack channel.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants