mirror of
https://github.com/Sea-Haven-Industries/.github.git
synced 2026-10-07 09:19:00 +00:00
A stale event base SHA was unioning commits already on main into the isolation diff, so a clean PR failed as a mixed app and Terraform change.
71 lines
2.6 KiB
YAML
71 lines
2.6 KiB
YAML
name: App and Terraform isolation
|
|
description: Fail when a change set mixes Terraform with deployable application files.
|
|
|
|
inputs:
|
|
app-paths:
|
|
description: Newline-separated deployable paths. A trailing slash is a prefix. Any other entry is an exact file.
|
|
required: true
|
|
terraform-dir:
|
|
description: Directory containing Terraform sources.
|
|
required: true
|
|
default: terraform
|
|
event-name:
|
|
description: github.event_name from the calling workflow.
|
|
required: true
|
|
pr-base-sha:
|
|
description: pull_request base SHA. Empty outside pull_request.
|
|
required: false
|
|
default: ""
|
|
merge-group-base-sha:
|
|
description: merge_group base SHA. Empty outside merge_group.
|
|
required: false
|
|
default: ""
|
|
|
|
runs:
|
|
using: composite
|
|
steps:
|
|
- name: Classify changed paths
|
|
shell: bash
|
|
working-directory: ${{ github.workspace }}
|
|
env:
|
|
APP_PATHS: ${{ inputs.app-paths }}
|
|
TERRAFORM_DIR: ${{ inputs.terraform-dir }}
|
|
EVENT_NAME: ${{ inputs.event-name }}
|
|
PR_BASE_SHA: ${{ inputs.pr-base-sha }}
|
|
MERGE_GROUP_BASE_SHA: ${{ inputs.merge-group-base-sha }}
|
|
CHECKER: ${{ github.action_path }}/check_app_terraform_isolation.py
|
|
run: |
|
|
set -euo pipefail
|
|
classify() {
|
|
python3 "${CHECKER}"
|
|
}
|
|
case "${EVENT_NAME}" in
|
|
pull_request)
|
|
if [[ -z "${PR_BASE_SHA}" ]]; then
|
|
echo "FAIL: pull_request base SHA is empty" >&2
|
|
exit 1
|
|
fi
|
|
# pull_request checkout is the merge commit. Diff that commit
|
|
# against its first parent so commits already on the base are
|
|
# not classified with this PR. Fall back when HEAD is not a merge.
|
|
if git rev-parse --verify --quiet HEAD^2 >/dev/null; then
|
|
git diff --name-only --diff-filter=ACMRD HEAD^1 HEAD | classify
|
|
else
|
|
merge_base="$(git merge-base "${PR_BASE_SHA}" HEAD)"
|
|
git diff --name-only --diff-filter=ACMRD "${merge_base}" HEAD | classify
|
|
fi
|
|
;;
|
|
merge_group)
|
|
if [[ -z "${MERGE_GROUP_BASE_SHA}" ]]; then
|
|
echo "FAIL: merge_group base SHA is empty" >&2
|
|
exit 1
|
|
fi
|
|
while IFS= read -r sha; do
|
|
[[ -z "${sha}" ]] && continue
|
|
git diff --name-only --diff-filter=ACMRD "${sha}^" "${sha}" | classify
|
|
done < <(git rev-list --reverse --first-parent "${MERGE_GROUP_BASE_SHA}..HEAD")
|
|
;;
|
|
*)
|
|
echo "SKIP: live isolation runs on pull_request and merge_group (event: ${EVENT_NAME})"
|
|
;;
|
|
esac
|