afterhours-shift-manager/tests/infra/test_hcp_contract.py
Adam Moussa 13350b72d0
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
feat(infra): migrate afterhours to HCP Terraform (PLAT-74) (#252)
* fix(cutover): write Slack secrets into empty Terraform shells

DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset.

* feat(infra): migrate afterhours to HCP Terraform (PLAT-74)

Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main.

* fix(cutover): retry DDB unprocessed items and skip past at() holidays

Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
2026-09-15 23:31:59 +00:00

92 lines
2.9 KiB
Python

"""Contracts for the HCP Terraform seam (PLAT-74)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[2]
TERRAFORM = ROOT / "terraform"
LAMBDA_TF = (TERRAFORM / "lambda.tf").read_text()
HCP_IAM = (TERRAFORM / "hcp_iam.tf").read_text()
DEPLOY = (ROOT / ".github" / "workflows" / "deploy.yaml").read_text()
CI = (ROOT / ".github" / "workflows" / "ci.yaml").read_text()
LOCALS = (TERRAFORM / "locals.tf").read_text()
def test_sam_template_removed():
assert not (ROOT / "template.yaml").exists()
assert not (ROOT / "samconfig.toml.example").exists()
def test_lambda_ignore_changes_includes_code_attributes():
for attr in (
"filename",
"s3_bucket",
"s3_key",
"s3_object_version",
"source_code_hash",
):
assert attr in LAMBDA_TF
assert "lifecycle" in LAMBDA_TF
assert "ignore_changes" in LAMBDA_TF
def test_schedules_disabled_by_default():
chunk = (TERRAFORM / "variables.tf").read_text().split('variable "schedules_enabled"')[1]
chunk = chunk.split("variable ")[0]
assert "default = false" in chunk or "default = false" in chunk
def test_prod_only_workspace():
versions = (TERRAFORM / "versions.tf").read_text()
assert "afterhours-shift-manager-prod" in versions
assert "afterhours-shift-manager-dev" not in versions
assert 'environment = "prod"' in LOCALS
assert "seahaven-dev" not in LOCALS
def test_in_repo_hcptf_roles():
assert 'apply_role = "hcptf-afterhours-shift-manager"' in LOCALS
assert 'plan_role = "hcptf-afterhours-shift-manager-plan"' in LOCALS
assert "hcptf_apply" in HCP_IAM
assert "DenyCreatePolicy" in HCP_IAM
def test_deploy_workflow_is_prod_zip_cd():
assert "release: published" not in DEPLOY
assert "cd-sam" not in DEPLOY
assert "environment: prod" in DEPLOY
assert "deploy-afterhours-prod" in DEPLOY
assert "gh release create" not in DEPLOY
assert "package_lambdas.py" in DEPLOY
assert "update-function-code" in DEPLOY
def test_ci_runs_pytest_and_terraform_validate():
assert "ci-python-sam" not in CI
assert "pytest" in CI
assert "terraform fmt -check" in CI
assert "terraform init -backend=false" in CI
assert "terraform validate" in CI
def test_seven_functions_named():
for name in (
"afterhours-shift-manager",
"afterhours-weekly-post",
"afterhours-roster-sync",
"afterhours-roster-api",
"afterhours-ring-scheduler",
"afterhours-holiday-router",
"afterhours-release-notifier",
):
assert name in LOCALS
def test_weekly_post_role_is_tf_managed_name():
assert 'role_name = "afterhours-shift-manager-weekly-post"' in LOCALS
def test_github_deploy_trust_is_main_only():
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
assert "refs/heads/${var.github_deploy_branch}" in iam
assert "refs/tags/v*" not in iam
assert "environment:prod" in iam or "environment:prod" in LOCALS