From 65c1ed86e1fcc672f12588ed88d80510042b4f38 Mon Sep 17 00:00:00 2001 From: Alexandre Brandizzi Date: Wed, 16 Sep 2026 16:07:16 -0300 Subject: [PATCH] docs(terraform): document staging token scope --- terraform/live/README.md | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/terraform/live/README.md b/terraform/live/README.md index c89fa0e..07a6f25 100644 --- a/terraform/live/README.md +++ b/terraform/live/README.md @@ -160,10 +160,16 @@ and GitHub deploys on pushes to `staging` and on manual `workflow_dispatch`. ### Credentials and enablement -Store a dedicated HCP team token only as the GitHub `dev` environment secret -`TF_API_TOKEN`. Scope it to workspace `shoc-backend-dev`. Plan JSON download -requires workspace admin on that one workspace. Do not grant project admin, -workspace create/move/delete, or staging access. Rotate at least every 90 days. +Store dedicated HCP team tokens as the GitHub environment secret `TF_API_TOKEN`: + +- `dev`: use a token scoped only to workspace `shoc-backend-dev`. +- `staging`: use a separate token scoped only to workspace + `shoc-backend-staging`. + +Plan JSON download requires workspace admin on the corresponding workspace. Do +not grant project admin or workspace create/move/delete permissions. Do not rely +on a repository-level token or reuse the dev-scoped token for staging. Rotate +each token at least every 90 days. Repository variable `TERRAFORM_APP_CD_ENABLED` starts unset/false so pushes to `dev` do not deploy. `workflow_dispatch` on `dev` still runs a release for the