mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 05:23:15 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD. * chore(iam): add Checkov skip comments for HCP IAM documents Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
91 lines
2.2 KiB
YAML
91 lines
2.2 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
pytest:
|
|
name: Pytest
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
|
with:
|
|
python-version: "3.12"
|
|
|
|
- name: Install test dependencies
|
|
run: |
|
|
set -euo pipefail
|
|
python -m pip install --upgrade pip
|
|
pip install -r tests/requirements.txt
|
|
pip install -r lambdas/classifier/requirements.txt
|
|
pip install -r lambdas/slack_post/requirements.txt
|
|
|
|
- name: Pytest
|
|
run: pytest
|
|
|
|
terraform:
|
|
name: Terraform
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
defaults:
|
|
run:
|
|
working-directory: terraform
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
|
|
with:
|
|
terraform_version: "1.16.0"
|
|
terraform_wrapper: false
|
|
|
|
- name: Terraform fmt
|
|
run: terraform fmt -check -recursive
|
|
|
|
- name: Terraform init
|
|
run: terraform init -backend=false
|
|
|
|
- name: Terraform validate
|
|
run: terraform validate
|
|
|
|
ci:
|
|
name: ci / ci
|
|
needs: [pytest, terraform]
|
|
if: ${{ always() && !cancelled() }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Check jobs
|
|
env:
|
|
PYTEST_RESULT: ${{ needs.pytest.result }}
|
|
TERRAFORM_RESULT: ${{ needs.terraform.result }}
|
|
run: |
|
|
set -euo pipefail
|
|
fail=0
|
|
check() {
|
|
local name="$1"
|
|
local result="$2"
|
|
case "${result}" in
|
|
success)
|
|
echo "${name}: ${result}"
|
|
;;
|
|
*)
|
|
echo "${name}: ${result}" >&2
|
|
fail=1
|
|
;;
|
|
esac
|
|
}
|
|
check pytest "${PYTEST_RESULT}"
|
|
check terraform "${TERRAFORM_RESULT}"
|
|
exit "${fail}"
|