> ## Documentation Index
> Fetch the complete documentation index at: https://docs.authsignal.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Promote a change from dev

> Capture a change made in the dev tenant in the module and roll it out to QA and production.

Day to day, changes are made in the dev tenant first. You then update the module to match and roll it out to QA and production.

## Prerequisites

* All environments set up, as in [Import the dev tenant into Terraform](/knowledge-base/terraform/import-dev) and [Add a new environment](/knowledge-base/terraform/add-environment).

```mermaid theme={null}
flowchart LR
    A["Change dev<br>in the portal"] --> B["Update the module<br>until dev plan<br>shows no changes"]
    B --> C["Pull request"]
    C --> D["QA"]
    D --> E["Production"]
```

<Warning>
  While `terraform plan` in dev still shows changes, don't apply in dev. The module is still the old version, so applying would undo your portal change.
</Warning>

## A changed resource

Run `terraform plan` in `envs/dev`. It lists each attribute that differs, as described in [Reading a plan](/knowledge-base/terraform/repository-setup#reading-a-plan). On each line, the left side is what the tenant has now and the right side is what the module has.

```text theme={null}
~ primary_color = "#2563EB" -> "#1D4ED8"
```

Copy the left-side value into the module and plan again. If the module sets that attribute from a variable, such as `webhook_url = var.email_otp_webhook_url`, change the value in `envs/dev/terraform.tfvars` instead. Repeat until the plan reports `No changes`.

For the flow, it's easier to regenerate the block than to edit it. Use a scratch folder with just the flow's import, as in [Generate code from the dev tenant](/knowledge-base/terraform/generate-code).

```hcl theme={null}
# scratch/main.tf
terraform {
  required_providers {
    authsignal = {
      source  = "authsignal/authsignal"
      version = "~> 3.12"
    }
  }
}

provider "authsignal" {}

import {
  to = authsignal_flow.sign_in
  id = "sign-in" # the flow's action code
}
```

With the dev [environment variables](/knowledge-base/terraform/repository-setup#connecting-to-a-tenant) set, run:

```bash theme={null}
cd scratch
terraform init
terraform plan -generate-config-out=generated.tf
```

Then replace the `flow = jsonencode(...)` part of the module's block with the generated one. Keep the `depends_on` lines. Delete the scratch folder when you're done. `-generate-config-out` won't overwrite an existing `generated.tf`.

## A new resource

The resources the provider supports, and the import ID each one takes, are listed on the [Terraform Registry](https://registry.terraform.io/providers/authsignal/authsignal/latest/docs).

1. Generate it in a scratch folder with one import block, as above.
2. Move it into the module, as in [Build the module from the generated code](/knowledge-base/terraform/build-module).
3. Add an `envs/dev/imports.tf` with its `module.authsignal.` address, as in [Import the dev tenant into Terraform](/knowledge-base/terraform/import-dev).
4. Plan in dev. Expect `1 to import, 0 to add, 0 to change, 0 to destroy`.
5. Apply, then delete `imports.tf` and `tfplan`.

In the other environments, the resource is created, so their plans show `1 to add`.

## A removed resource

Delete it in the dev tenant and remove its block from the module. In dev, the plan has nothing left to do. In the other environments, the plan shows it being destroyed.

## Roll it out

1. Commit the module changes and open a pull request.
2. After it merges, run the [QA pipeline](/knowledge-base/terraform/repository-setup#running-qa-and-production).
3. Check the plan lists only the changes you made. Anything else usually means someone changed that tenant by hand. Find out why before approving.
4. Approve the apply.
5. Repeat for production.

## Edits outside dev

Changes made to existing resources in the QA or production tenants are reverted the next time Terraform is applied there. Anything new added in those tenants isn't managed by Terraform and is left alone. Dev should be the only tenant anyone edits by hand.

<Tip>
  `terraform plan -refresh-only` in dev lists what changed in the tenant without proposing any changes.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.