Section 3 · CI/CD automation

How the pieces fit together in a CI/CD pipeline

Estimated time: 1 min

CI/CD pipeline flow

This diagram shows the end-to-end pipeline from code commit to deployed resources.

Diagram showing CI/CD pipeline: on pull request, HCL code flows through Terraform plan and PR comment stages; on merge to main, it continues through Terraform apply to live resources in Grafana

What each stage does

The pipeline has two stages, each triggered at a different point in the workflow.

StageTriggerAction
PlanEvery pushShow what Terraform will change
ApplyMerge to main onlyDeploy changes to Grafana

When each path runs

The same stages run along two paths, depending on where the code is in the workflow:

  • On a pull request: the pipeline runs plan, then posts the plan as a PR comment for review. Nothing is deployed yet.
  • On merge to main: the pipeline runs plan and apply. Terraform applies the changes, so the resources in Grafana always reflect the latest code on main.

The review gate

The Terraform plan output is posted as a PR comment so you can see:

  • Which resources will be created, updated, or destroyed
  • Exactly what configuration will change

This gives you the full benefits of resources as code: every change is reviewed, every deployment is automated, and you can trace any resource back to the commit that produced it.