docs(terraform): document staging token scope

This commit is contained in:
Alexandre Brandizzi 2026-09-16 16:07:16 -03:00
parent 4ae6d02d55
commit 65c1ed86e1

View file

@ -160,10 +160,16 @@ and GitHub deploys on pushes to `staging` and on manual `workflow_dispatch`.
### Credentials and enablement
Store a dedicated HCP team token only as the GitHub `dev` environment secret
`TF_API_TOKEN`. Scope it to workspace `shoc-backend-dev`. Plan JSON download
requires workspace admin on that one workspace. Do not grant project admin,
workspace create/move/delete, or staging access. Rotate at least every 90 days.
Store dedicated HCP team tokens as the GitHub environment secret `TF_API_TOKEN`:
- `dev`: use a token scoped only to workspace `shoc-backend-dev`.
- `staging`: use a separate token scoped only to workspace
`shoc-backend-staging`.
Plan JSON download requires workspace admin on the corresponding workspace. Do
not grant project admin or workspace create/move/delete permissions. Do not rely
on a repository-level token or reuse the dev-scoped token for staging. Rotate
each token at least every 90 days.
Repository variable `TERRAFORM_APP_CD_ENABLED` starts unset/false so pushes to
`dev` do not deploy. `workflow_dispatch` on `dev` still runs a release for the