Skip to content

Forgeplane Selective Undo

Forgeplane Selective Undo is a gated, evidence-first workflow for removing one historical, accepted input change from a Terraform or OpenTofu instance. It creates a new change against current managed state; it does not restore historical state, replay an old apply, or let an operator select arbitrary resource addresses for deletion.

Step through a fixed example that removes an eligible historical input change while retaining an unrelated later change. Evidence, approval, and a fresh apply are separate steps; every event is simulated and advances only when you choose it.

Remove one change. Keep the later one.Interactive demo

All inputs, evidence, approvals, runs, and state generations are simulated. This illustrates the workflow, not the exact product UI. Nothing connects to Forgeplane or changes infrastructure.

This fixed example assumes eligible, non-secret revisions and matching provenance and execution identities. Drift, later edits to replicas, changed lineage or state, expanded candidate impact, or recovery_required would stop the real workflow.

Step 1 of 8

Select an accepted input change

R2 changed replicas from 2 to 3. R3 later changed owner to payments. Removing R2 should retain that unrelated owner change, not restore R1. The target below is illustrative, not accepted.

  1. R1

    Parent revision

    replicas
    2
    owner
    platform
  2. R2

    Selected change

    replicas
    3
    owner
    platform
  3. R3

    Later change

    replicas
    3
    owner
    payments

Source apply: demo-source · R2 · succeeded
Historical revisions and prior state generations stay in the audit history.

Current accepted inputs

Revision
R3
replicas
3
owner
payments
State generation
3

Illustrative target · not accepted

replicas
2 · selected change removed
owner
payments · later change retained

New change against current managed state, not an old state restore.

Fresh baseline
Not checked
Candidate evidence
Not checked
Removal change
Not created
Separate approval
Not requested
Fresh apply
Not created

The source must be a successful applied run tied to an accepted input revision with a parent. Forgeplane checks:

  • the selected and current accepted revisions and their template/version lineage;
  • the managed-state object and generation;
  • immutable source, tool version, provider-lock, and schema identities; and
  • a complete, digest-bound, value-free source-plan evidence manifest.

Secret-bearing input revisions are ineligible. Missing provenance, later changes that touch the selected inputs, drift, changed lineage or state, and expanded candidate impact block the workflow. Do not bypass a refusal by editing persisted evidence or state.

Use the run detail UI to follow these phases:

  1. Check the source run’s eligibility and the accepted input change proposed for removal.
  2. Start an evidence-only baseline check. API clients use a stable Idempotency-Key for the check request.
  3. Wait for a clean baseline. Do not continue while it is running, blocked, failed, or stale.
  4. Start a fresh candidate plan for the proposed input-change removal.
  5. Review its evidence for contained impact and matching current lineage, execution identity, and state generation. The candidate is internal evidence, not an executable or directly promotable apply run.
  6. Explicitly create the removal change. This step does not create an approval or queue an apply.
  7. Request approval through the normal workflow. A distinct authorized approver reviews the change; the approved operation is a fresh ordinary apply.
  8. Verify the new accepted revision, managed-state generation, and undo lineage after finalization. If mutation may have happened but state cannot be verified, stop and follow managed-state recovery.

The source run and prior state generations remain in the audit history. Canceling or failing the new run does not relabel the source as rolled back.

Selective Undo must be enabled for the target environment, with approvals.enabled enabled before execution. The removal change follows the normal approval workflow; source-run approval and candidate evidence do not authorize its apply. Feature gates do not bypass permissions, artifact checks, or separation of duties.

Keep both selective_undo.preview.enabled and selective_undo.create.enabled disabled until backups, permissions, provenance, and operator observability are ready. Enable preview first, review its evidence outcomes in one controlled environment, then enable creation only when the operating controls are acceptable. See Feature gates for the rollout order.

  • Use Selective Undo only for accepted input changes Forgeplane can prove eligible.
  • Generate new evidence after any relevant state or definition change.
  • Do not use it to accept drift, edit configuration, or restore an arbitrary historical state.
  • Do not use it while managed state is recovery_required; complete and verify state recovery first.
  • Do not treat a canceled or failed removal run as a rollback of the source run.

Before enabling state-changing removal, verify the managed-state backup and recovery procedure and the approval workflow.