mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 06:43:12 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* fix(cutover): write Slack secrets into empty Terraform shells DescribeSecret succeeds on HCP-created shells with no version, so skip-if-exists left roster and Slack tokens unset. * feat(infra): migrate afterhours to HCP Terraform (PLAT-74) Replace the mgmt SAM stack with a prod-only HCP workspace, in-repo hcptf IAM, stub Lambdas, and zip CD on push to main. * fix(cutover): retry DDB unprocessed items and skip past at() holidays Unprocessed BatchWriteItem rows and leftover past at() schedules would drop roster data or abort holiday recreation during prod cutover.
92 lines
2.9 KiB
Python
92 lines
2.9 KiB
Python
"""Contracts for the HCP Terraform seam (PLAT-74)."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[2]
|
|
TERRAFORM = ROOT / "terraform"
|
|
LAMBDA_TF = (TERRAFORM / "lambda.tf").read_text()
|
|
HCP_IAM = (TERRAFORM / "hcp_iam.tf").read_text()
|
|
DEPLOY = (ROOT / ".github" / "workflows" / "deploy.yaml").read_text()
|
|
CI = (ROOT / ".github" / "workflows" / "ci.yaml").read_text()
|
|
LOCALS = (TERRAFORM / "locals.tf").read_text()
|
|
|
|
|
|
def test_sam_template_removed():
|
|
assert not (ROOT / "template.yaml").exists()
|
|
assert not (ROOT / "samconfig.toml.example").exists()
|
|
|
|
|
|
def test_lambda_ignore_changes_includes_code_attributes():
|
|
for attr in (
|
|
"filename",
|
|
"s3_bucket",
|
|
"s3_key",
|
|
"s3_object_version",
|
|
"source_code_hash",
|
|
):
|
|
assert attr in LAMBDA_TF
|
|
assert "lifecycle" in LAMBDA_TF
|
|
assert "ignore_changes" in LAMBDA_TF
|
|
|
|
|
|
def test_schedules_disabled_by_default():
|
|
chunk = (TERRAFORM / "variables.tf").read_text().split('variable "schedules_enabled"')[1]
|
|
chunk = chunk.split("variable ")[0]
|
|
assert "default = false" in chunk or "default = false" in chunk
|
|
|
|
|
|
def test_prod_only_workspace():
|
|
versions = (TERRAFORM / "versions.tf").read_text()
|
|
assert "afterhours-shift-manager-prod" in versions
|
|
assert "afterhours-shift-manager-dev" not in versions
|
|
assert 'environment = "prod"' in LOCALS
|
|
assert "seahaven-dev" not in LOCALS
|
|
|
|
|
|
def test_in_repo_hcptf_roles():
|
|
assert 'apply_role = "hcptf-afterhours-shift-manager"' in LOCALS
|
|
assert 'plan_role = "hcptf-afterhours-shift-manager-plan"' in LOCALS
|
|
assert "hcptf_apply" in HCP_IAM
|
|
assert "DenyCreatePolicy" in HCP_IAM
|
|
|
|
|
|
def test_deploy_workflow_is_prod_zip_cd():
|
|
assert "release: published" not in DEPLOY
|
|
assert "cd-sam" not in DEPLOY
|
|
assert "environment: prod" in DEPLOY
|
|
assert "deploy-afterhours-prod" in DEPLOY
|
|
assert "gh release create" not in DEPLOY
|
|
assert "package_lambdas.py" in DEPLOY
|
|
assert "update-function-code" in DEPLOY
|
|
|
|
|
|
def test_ci_runs_pytest_and_terraform_validate():
|
|
assert "ci-python-sam" not in CI
|
|
assert "pytest" in CI
|
|
assert "terraform fmt -check" in CI
|
|
assert "terraform init -backend=false" in CI
|
|
assert "terraform validate" in CI
|
|
|
|
|
|
def test_seven_functions_named():
|
|
for name in (
|
|
"afterhours-shift-manager",
|
|
"afterhours-weekly-post",
|
|
"afterhours-roster-sync",
|
|
"afterhours-roster-api",
|
|
"afterhours-ring-scheduler",
|
|
"afterhours-holiday-router",
|
|
"afterhours-release-notifier",
|
|
):
|
|
assert name in LOCALS
|
|
|
|
|
|
def test_weekly_post_role_is_tf_managed_name():
|
|
assert 'role_name = "afterhours-shift-manager-weekly-post"' in LOCALS
|
|
|
|
|
|
def test_github_deploy_trust_is_main_only():
|
|
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
|
|
assert "refs/heads/${var.github_deploy_branch}" in iam
|
|
assert "refs/tags/v*" not in iam
|
|
assert "environment:prod" in iam or "environment:prod" in LOCALS
|