name: CI on: pull_request: branches: [main] merge_group: permissions: contents: read jobs: pytest: name: Pytest runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: python-version: "3.12" - name: Install test dependencies run: | set -euo pipefail python -m pip install --upgrade pip pip install -r tests/requirements.txt pip install -r src/slack-bot/requirements.txt pip install -r src/weekly-post/requirements.txt pip install -r src/shared/requirements.txt pip install -r src/portal-api/requirements.txt pip install -r requirements-api.txt - name: Pytest run: pytest terraform: name: Terraform runs-on: ubuntu-latest timeout-minutes: 15 defaults: run: working-directory: terraform steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1 with: terraform_version: "1.16.0" terraform_wrapper: false - name: Terraform fmt run: terraform fmt -check -recursive - name: Terraform init run: terraform init -backend=false - name: Terraform validate run: terraform validate ci: name: ci / ci needs: [pytest, terraform] if: ${{ always() && !cancelled() }} runs-on: ubuntu-latest timeout-minutes: 5 steps: - name: Check jobs env: PYTEST_RESULT: ${{ needs.pytest.result }} TERRAFORM_RESULT: ${{ needs.terraform.result }} run: | set -euo pipefail fail=0 check() { local name="$1" local result="$2" case "${result}" in success) echo "${name}: ${result}" ;; *) echo "${name}: ${result}" >&2 fail=1 ;; esac } check pytest "${PYTEST_RESULT}" check terraform "${TERRAFORM_RESULT}" exit "${fail}"