IACM Workspaces: Support Docker Registry as an Alternative TF/OpenTofu Source (Instead of GitHub Clone)
S
Satisfied Lark
Description:
Infrastructure as Code Management (IACM) workspaces currently source their Terraform/OpenTofu code exclusively via git clone from a GitHub repository, with the working directory determined by the configured base_path. This creates a hard dependency on GitHub access for every plan/apply run.
We request support for a Docker registry as an alternative source for a workspace’s TF/OpenTofu code, in place of the GitHub clone step. In this model:
The IaC source code is packaged into a Docker image as part of a CI process.
The IACM workspace is configured to pull its TF/OpenTofu code from that image in a registry, rather than cloning a git repo — using an image-internal path analogous to today’s base_path.
This should be additive: workspaces should be able to choose “Git” or “Docker Image” as their source type, with git-based cloning remaining fully supported and unchanged for existing workspaces. The detection/trigger mechanism for new image pushes (webhook, polling, etc.) is left to Harness to decide.
Business Impact:
Works in air-gapped / restricted-network environments: Enables IACM to provision infrastructure where the execution runner has no access to GitHub at all, only to an internal/private container registry.
Immutable, versioned execution: Running against a pinned image tag rather than a live branch/commit eliminates drift between what was reviewed/built and what actually gets applied.
Removes GitHub as a single point of failure: If GitHub is unavailable or unreachable, provisioning can still proceed as long as the registry is reachable.