Current accepted inputs
- Revision
- R3
- replicas
3- owner
payments- State generation
- 3
Forgeplane Selective Undo is a gated, evidence-first workflow for removing one historical, accepted input change from a Terraform or OpenTofu instance. It creates a new change against current managed state; it does not restore historical state, replay an old apply, or let an operator select arbitrary resource addresses for deletion.
Step through a fixed example that removes an eligible historical input change while retaining an unrelated later change. Evidence, approval, and a fresh apply are separate steps; every event is simulated and advances only when you choose it.
All inputs, evidence, approvals, runs, and state generations are simulated. This illustrates the workflow, not the exact product UI. Nothing connects to Forgeplane or changes infrastructure.
This fixed example assumes eligible, non-secret revisions and matching provenance and execution identities. Drift, later edits to replicas, changed lineage or state, expanded candidate impact, or recovery_required would stop the real workflow.
Step 1 of 8
R2 changed replicas from 2 to 3. R3 later changed owner to payments. Removing R2 should retain that unrelated owner change, not restore R1. The target below is illustrative, not accepted.
Parent revision
2platformSelected change
3platformLater change
3paymentsSource apply: demo-source · R2 · succeeded
Historical revisions and prior state generations stay in the audit history.
3payments2 · selected change removedpayments · later change retainedNew change against current managed state, not an old state restore.
The source must be a successful applied run tied to an accepted input revision with a parent. Forgeplane checks:
Secret-bearing input revisions are ineligible. Missing provenance, later changes that touch the selected inputs, drift, changed lineage or state, and expanded candidate impact block the workflow. Do not bypass a refusal by editing persisted evidence or state.
Use the run detail UI to follow these phases:
Idempotency-Key for the check request.The source run and prior state generations remain in the audit history. Canceling or failing the new run does not relabel the source as rolled back.
Selective Undo must be enabled for the target environment, with approvals.enabled enabled before execution. The removal change follows the normal approval workflow; source-run approval and candidate evidence do not authorize its apply. Feature gates do not bypass permissions, artifact checks, or separation of duties.
Keep both selective_undo.preview.enabled and selective_undo.create.enabled disabled until backups, permissions, provenance, and operator observability are ready. Enable preview first, review its evidence outcomes in one controlled environment, then enable creation only when the operating controls are acceptable. See Feature gates for the rollout order.
recovery_required; complete and verify state recovery first.Before enabling state-changing removal, verify the managed-state backup and recovery procedure and the approval workflow.