Skip to main content

Pipeline Operations

Last updated on

Harness IaCM pipelines support several operational features that help you manage infrastructure changes safely and efficiently. These operations integrate into your provision workflows to add approval gates, score deployment risk with AI analysis, detect configuration drift, automate pull request reviews, and prevent concurrent execution conflicts.

This guide covers the available pipeline operations and when to use each one.


Before you begin

  • Harness account with IaCM enabled: You need Infrastructure as Code Management under Infrastructure in Harness when it is entitled on your account. Go to Getting started with Harness Platform to access or create a Harness account.

    Contact Harness support

    If IaCM does not appear, go to Get started with IaCM, or contact your account administrator or Harness Support.

  • Pipeline permissions: You need View, Create/Edit, and Execute for Pipelines. Go to RBAC in Harness to review the permissions model, and go to Manage roles to assign a role that includes them.

  • Approval permissions (for Approval step): Users who approve or reject plans need Approve permission for the relevant pipeline or stage. Go to Pipeline permissions to review the required permissions, and go to Approvals in Harness to configure the Approval step.

  • Existing provision pipeline: You need a pipeline with an IaCM stage that includes Plan and Apply steps. Go to Provision workspace to create one.


Available operations

Choose the operation that fits your workflow:

OperationUse caseWhen to use
AI Blast Radius AgentScore deployment risk and visualize resource dependencies from a Terraform or OpenTofu planWhen you want engineers and approvers to see a risk score, plain-language summary, and dependency graph before applying changes
Approval stepReview and approve infrastructure changes before applying themWhen you need manual review of Terraform plan output, cost estimates, or policy evaluation before applying changes
Queue stepSerialize pipeline executions targeting the same workspaceWhen multiple pipelines or triggers could run concurrently against the same workspace, preventing state file conflicts
Drift detectionIdentify manual changes made outside of your IaC workflowWhen you want to detect resources created or modified directly in the cloud console instead of through code
PR automationAutomatically post Terraform plan output as pull request commentsWhen your team reviews infrastructure changes via GitHub, GitLab, or Bitbucket pull requests before merging

Operation guides

Select an operation to view the full guide:

AI Blast Radius Agent

The AI Blast Radius Agent step analyzes your Terraform or OpenTofu plan output and returns a 1–10 risk score, a plain-language summary of the main risk drivers, and an interactive resource dependency graph. Because it is a standalone pipeline step with dedicated configuration options, it has its own guide.

Go to AI Blast Radius Agent to add it to your pipeline.


Troubleshooting

Approval step times out after 60 minutes in Harness IaCM pipeline

The default approval timeout is 60 minutes. You can configure this in the approval step settings. If the step times out, the pipeline fails and you need to re-run it.

Permission denied when trying to approve or reject IaCM approval step

Ensure you have Approve permissions for the pipeline or stage. Contact your administrator to assign the required role, or go to the RBAC in Harness documentation to review required permissions.

IaCM approval step not showing plan details or resource changes

Verify that the Plan step completed successfully before the Approval step. Check the Plan step logs for errors. If the plan generated no changes, the approval may show empty resource lists.

Approval step shows incomplete cost estimation data

Cost estimation requires Infracost integration and depends on cloud provider API availability. Check that your workspace has cost estimation enabled and that the provider credentials are valid.

Queue step not preventing concurrent executions in IaCM pipeline

Verify that all pipelines targeting the same workspace use the exact same resource key. Check the Queue step configuration in each pipeline and ensure consistency.

Pipeline applies outdated plan after being queued

Place the Queue step before the Plan step, not between Plan and Apply. A queued pipeline may resume with an outdated plan if the Queue step is placed incorrectly.

Drift detection pipeline shows no drift but manual changes exist

Verify that the workspace state file is up to date. Run a plan-refresh-only operation first to sync the state, then run drift detection again.

PR automation not posting Terraform plan as comment in pull request

Check that the webhook trigger is configured correctly with the same connector as the workspace. For public repositories, add the HARNESS_PASSWORD_API environment variable with your git token.

IACM Blast Radius Agent step fails with a missing plan file error

The Blast Radius Agent step requires a Terraform or OpenTofu plan step to run immediately before it in the same IaCM stage. Add a plan step before the Blast Radius Agent step and re-run the pipeline.

AI Blast Radius Analysis banner does not appear on the Resources tab after the Blast Radius Agent step completes

Verify that you have been granted access to the AI Blast Radius Agent Beta. If access is confirmed and the step completed without errors, refresh the pipeline execution page. If the banner still does not appear, contact Harness Support.


Next steps

You have reviewed the available IaCM pipeline operations. Choose the operations that fit your team's workflow and add them to your provision pipelines.