What is a promotion gate?
A promotion gate is a check that an infrastructure or configuration change must pass before it advances between environments, for example staging to production; it normally calls for approval and assesses policy or coverage conditions.
Why it matters
NIST SP 800-128 and similar change management guidance call for review and approval before a change takes effect. Many audits also look for approval by someone other than the author. When configured to do so, a promotion gate checks this where the change becomes live, and it records the result.
How compliance.tf applies it
Within compliance.tf, each environment is tied to a config snapshot. Promotion means attaching a new snapshot to that environment. Protected environments, with production protected by default, execute the gate before anything changes:
| Check | Severity | Raised when |
|---|---|---|
null_candidate_snapshot | block | No candidate snapshot was provided |
snapshot_not_approved | block | The candidate snapshot lacks approval |
sod_self_approval | block | Segregation of duties is enabled and the promoter is also the snapshot publisher |
coverage_uncovered | block or warn, controlled by the organization's coverage setting | An enabled framework contains clauses that the candidate leaves uncovered |
The promotion continues only when no check reports block severity.
- Preview: executes the identical gate without changing state. Because a
warnoutcome appears only in the preview response, save that response if the warning must remain on file. - Audit record: the promotion and its audit record commit as one atomic operation; a simultaneous change fails with HTTP 409.
- Waivers (accepted exceptions stored alongside a promotion): fixed when promotion occurs. Later processing does not check their expiry again.
- Rollback: restores the prior snapshot and retains the waivers.
By default, segregation of duties is disabled.