Approvable previews

Plan a Helm or Terraform change from Actions on an installation, or a Helm change with ryvn command dry-run in the CLI, then hit Approve on the resulting task to apply the exact diff you reviewed, with no second run that could pick up different state. Appliability is decided when you request the preview rather than by the environment's approval policy: Disable approvals (or --disable-approvals) gives you a read-only plan, a Terraform preview from the CLI stays read-only so it never holds the state lock, and the previews Ryvn renders for pull requests and git sync are never appliable.