afterhours-shift-manager/tests/infra/test_hcp_contract.py
Adam Moussa 1362a6cd90
Some checks are pending
Deploy API / Resolve target (push) Waiting to run
Deploy API / Deploy API to (push) Blocked by required conditions
Deploy / Deploy to prod (push) Waiting to run
fix(infra): keep ecs-task-boundary CreatePolicy off live resources (PLAT-216) (#262)
Bootstrap is an IAM factory. The boundary must not wait on DynamoDB, SQS, ECR, or the ECS log group.
2026-09-21 19:57:12 +00:00

175 lines
6.3 KiB
Python

"""Contracts for the HCP Terraform seam (PLAT-74)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[2]
TERRAFORM = ROOT / "terraform"
LAMBDA_TF = (TERRAFORM / "lambda.tf").read_text()
HCP_IAM = (TERRAFORM / "hcp_iam.tf").read_text()
DEPLOY = (ROOT / ".github" / "workflows" / "deploy.yaml").read_text()
CI = (ROOT / ".github" / "workflows" / "ci.yaml").read_text()
LOCALS = (TERRAFORM / "locals.tf").read_text()
VARIABLES = (TERRAFORM / "variables.tf").read_text()
def test_sam_template_removed():
assert not (ROOT / "template.yaml").exists()
assert not (ROOT / "samconfig.toml.example").exists()
def test_lambda_ignore_changes_includes_code_attributes():
for attr in (
"filename",
"s3_bucket",
"s3_key",
"s3_object_version",
"source_code_hash",
):
assert attr in LAMBDA_TF
assert "lifecycle" in LAMBDA_TF
assert "ignore_changes" in LAMBDA_TF
def test_schedules_disabled_by_default():
chunk = (
(TERRAFORM / "variables.tf")
.read_text()
.split('variable "schedules_enabled"')[1]
)
chunk = chunk.split("variable ")[0]
assert "default = false" in chunk or "default = false" in chunk
def test_ecs_schedules_disabled_by_default():
chunk = (
(TERRAFORM / "variables.tf")
.read_text()
.split('variable "ecs_schedules_enabled"')[1]
)
chunk = chunk.split("variable ")[0]
assert "default = false" in chunk or "default = false" in chunk
def test_workspaces_use_app_tag():
versions = (TERRAFORM / "versions.tf").read_text()
assert 'tags = ["app:afterhours-shift-manager"]' in versions
assert 'name = "afterhours-shift-manager-prod"' not in versions
assert 'hcp_workspace = "${local.project}-${var.environment}"' in LOCALS
assert "seahaven-${var.environment}" in LOCALS
def test_ecs_ignore_changes_and_task_size():
ecs = (TERRAFORM / "ecs.tf").read_text()
assert "ignore_changes = [container_definitions]" in ecs
assert "ignore_changes = [task_definition, desired_count]" in ecs
assert 'cpu = "512"' in ecs
assert 'memory = "1024"' in ecs
assert 'cpu_architecture = "ARM64"' in ecs
assert 'path = "/api/health"' in ecs
def test_stack_owns_a_vpc_instead_of_looking_up_default():
vpc = (TERRAFORM / "vpc.tf").read_text()
ecs = (TERRAFORM / "ecs.tf").read_text()
assert 'resource "aws_vpc" "this"' in vpc
assert "cidr_block = local.vpc_cidr" in vpc
assert 'vpc_cidr = "10.70.0.0/16"' in LOCALS
assert 'data "aws_vpc" "default"' not in ecs
assert "data.aws_vpc.default" not in ecs
assert "data.aws_subnets.default" not in ecs
assert "aws_vpc.this.id" in ecs
assert "aws_subnet.public[*].id" in ecs
assert "ec2:CreateVpc" in HCP_IAM
assert "sid = \"RefreshVpc\"" in HCP_IAM
assert "afterhours-shift-manager-ecs" in HCP_IAM
assert "hcptf_apply_ecs" in HCP_IAM
def test_ecs_task_boundary_uses_static_arns():
iam = (TERRAFORM / "iam.tf").read_text()
chunk = iam.split('data "aws_iam_policy_document" "ecs_task_boundary"')[1]
chunk = chunk.split("resource ")[0]
assert "aws_dynamodb_table.shifts" not in chunk
assert "aws_sqs_queue.jobs" not in chunk
assert "aws_ecr_repository.api" not in chunk
assert "aws_cloudwatch_log_group.api" not in chunk
assert "table/${local.table_name}" in chunk
assert "log-group:/ecs/${local.project}" in chunk
def test_deploy_api_workflow_exists():
deploy_api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text()
assert "environment: ${{ needs.target.outputs.environment }}" in deploy_api
assert "/afterhours-shift-manager/deploy/cluster" in deploy_api
assert "linux/arm64" in deploy_api
assert "gh release create" in deploy_api
def test_in_repo_hcptf_roles():
assert 'apply_role = "hcptf-afterhours-shift-manager"' in LOCALS
assert 'plan_role = "hcptf-afterhours-shift-manager-plan"' in LOCALS
assert "hcptf_apply" in HCP_IAM
assert "DenyCreatePolicy" in HCP_IAM
def test_deploy_workflow_is_prod_zip_cd():
assert "release: published" not in DEPLOY
assert "cd-sam" not in DEPLOY
assert "environment: prod" in DEPLOY
assert "deploy-afterhours-prod" in DEPLOY
assert "gh release create" not in DEPLOY
assert "package_lambdas.py" in DEPLOY
assert "update-function-code" in DEPLOY
def test_ci_runs_pytest_and_terraform_validate():
assert "ci-python-sam" not in CI
assert "pytest" in CI
assert "terraform fmt -check" in CI
assert "terraform init -backend=false" in CI
assert "terraform validate" in CI
def test_checkcomponents_queue_arn_variable_matches_iam_references():
assert 'variable "checkcomponents_queue_arn"' in VARIABLES
assert "var.checkcomponents_queue_arn" in LAMBDA_TF
boundary = (TERRAFORM / "lambda_boundary.tf").read_text()
assert "var.checkcomponents_queue_arn" in boundary
data_tf = (TERRAFORM / "data.tf").read_text()
assert "dev_has_no_paychex" in data_tf
assert "checkcomponents_pair" in data_tf
def test_eight_functions_named():
for name in (
"afterhours-shift-manager",
"afterhours-weekly-post",
"afterhours-roster-sync",
"afterhours-roster-api",
"afterhours-ring-scheduler",
"afterhours-holiday-router",
"afterhours-release-notifier",
"afterhours-portal-api",
):
assert name in LOCALS
def test_weekly_post_role_is_tf_managed_name():
assert 'role_name = "afterhours-shift-manager-weekly-post"' in LOCALS
def test_github_deploy_trust_covers_zip_and_image():
iam = (TERRAFORM / "iam_github_deploy.tf").read_text()
assert "environment:prod" in iam or "environment:prod" in LOCALS
assert "environment:dev" in iam or "environment:dev" in LOCALS
assert "deploy.yaml@refs/heads/${var.github_deploy_branch}" in iam
assert "deploy-api.yaml@refs/heads/${var.github_deploy_branch}" in iam
assert "deploy-api.yaml@refs/tags/v*" in iam
assert "deploy.yaml@*" not in iam
assert "ecs:ListTasks" in iam
def test_plan_refresh_includes_provider6_s3_gets():
assert "s3:GetLifecycleConfiguration" in HCP_IAM
assert "s3:GetReplicationConfiguration" in HCP_IAM
assert "s3:GetBucketReplication" in HCP_IAM