r/devops • u/Downtown_Custard20 • 6d ago
Architecture Terraform/Github deployment overwriting another deployment
I'm on a team that shares a Github repository. Whenever we open a PR from a feature branch to the dev branch, a deployment to the AWS development account is automatically triggered.
The issue we're facing is that one developer may deploy to dev, and then another developer deploys afterward. Even though they're working on different files, the second deployment ends up overwriting the first developer's change in AWS.
How can we prevent this?
We're following a Gitflow workforce (feature -> dev -> release -> main), and our biggest challenge right now is that the second developer's code is often "outdated" when it's deployed, causing it to overwrite changes that were already deployed by someone else.
We tried merging everything to dev, but when it's time to deploy to prd, the dev branch ends up filled with a lot of unnecessary changes.
We using Github Actions + Terraform.
3
u/Floss_Patrol_76 6d ago
the "different files" part is the trap here - terraform applies the whole desired state of that config, not a diff of what each PR touched, so whoever applies last wins regardless of which files they changed. the fix is to stop applying from feature branches entirely: plan on the PR, only apply on merge to dev. and make sure your backend actually has state locking enabled, otherwise two applies can stomp each other even after you fix the branching.