Problem
IaCM currently has no equivalent of CD's Deployment Freeze Window. Freeze windows today can only be configured for CD modules (services/environments) — there's no option to freeze IaCM workspaces/pipelines.
Customer use case
Twilio periodically performs maintenance on Harness delegates (destroying and recreating them), during which delegates are unavailable for ~1 hour. Their IaCM pipelines (plan/apply) depend on those delegates, so any pipeline triggered during that window fails. They want a way to prevent IaCM pipelines from being triggered while delegate maintenance is in progress — i.e., a scheduled freeze window scoped to IaCM workspaces/pipelines, matching the capability CD already has.
Current workarounds:
  • OPA + Manual Approval gates — requires custom policy authoring per workspace/pipeline; not a first-class scheduled freeze.
  • Queue + Barrier steps with Approvals — same limitation; approval-based, not time-window-based, and puts the onus on manual intervention during the freeze rather than blocking automatically.
  • Manually locking the workspace — only viable if the freeze is workspace-scoped, and requires manual toggling before/after every maintenance window rather than a scheduled window.
None of these give a native, scheduled "no pipelines will run in this window" guarantee the way CD's freeze feature does.
Ask
Add Deployment Freeze Window support for IaCM, scoped at the workspace (and ideally pipeline/org/project) level, consistent with the existing CD freeze window model — so customers doing infra/delegate maintenance can block plan/apply execution for a defined time range without custom OPA policies or manual gating.
Created by Mayuresh Kshirsagar
·