Merge pull request #32 from Sea-Haven-Industries/fix/enable-ci-tests

fix(ci): enable Jest CDK stack tests (PLAT-90)
This commit is contained in:
Adam Moussa 2026-08-07 12:22:53 -04:00 • committed by GitHub
commit 0c939405fb
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
6 changed files with 4138 additions and 1 deletions

View file

@ -11,3 +11,4 @@ jobs:
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@81cf168170f356d1423d7736f7ce93fd6611ad53 # v1.0.4
with:
node-version: "24"
run-tests: true

22
.github/workflows/policy.yaml.yml vendored Normal file
View file

@ -0,0 +1,22 @@
name: PR Policy
on:
pull_request:
types: [opened, reopened, synchronize, edited, labeled, unlabeled, ready_for_review]
concurrency:
group: "policy-${{ github.event.pull_request.number }}"
cancel-in-progress: true
permissions:
contents: read
issues: read
pull-requests: read
jobs:
policy:
uses: Sea-Haven-Industries/.github/.github/workflows/callable-pr-policy.yaml@7ac3528750b346f181347bb09f6af927a1c0aa14 # v1.0.6
secrets:
JIRA_CLOUD_ID: ${{ secrets.JIRA_CLOUD_ID }}
JIRA_SERVICE_ACCOUNT_EMAIL: ${{ secrets.JIRA_SERVICE_ACCOUNT_EMAIL }}
JIRA_API_TOKEN: ${{ secrets.JIRA_API_TOKEN }}

3955
package-lock.json generated

File diff suppressed because it is too large Load diff

View file

@ -6,14 +6,19 @@
},
"scripts": {
"build": "tsc",
"test": "jest",
"cdk": "cdk",
"synth": "cdk synth",
"deploy": "cdk deploy",
"diff": "cdk diff"
},
"devDependencies": {
"@swc/core": "1.13.5",
"@swc/jest": "0.2.39",
"@types/jest": "29.5.14",
"@types/node": "^24.13.3",
"aws-cdk": "^2.1133.0",
"jest": "29.7.0",
"source-map-support": "^0.5.21",
"tsx": "4.23.1",
"typescript": "~7.0.2"
@ -21,5 +26,32 @@
"dependencies": {
"aws-cdk-lib": "2.262.1",
"constructs": "^10.7.1"
},
"jest": {
"testEnvironment": "node",
"roots": [
"<rootDir>/test"
],
"testMatch": [
"**/test/**/*.test.ts"
],
"transform": {
"^.+\\.tsx?$": [
"@swc/jest",
{
"jsc": {
"parser": {
"syntax": "typescript",
"tsx": false
},
"target": "es2022"
},
"module": {
"type": "commonjs"
}
}
]
},
"clearMocks": true
}
}

View file

@ -0,0 +1,127 @@
import * as cdk from "aws-cdk-lib";
import { Match, Template } from "aws-cdk-lib/assertions";
import * as fs from "node:fs";
import * as path from "node:path";
import { FileShareStack } from "../lib/file-share-stack";
const context = JSON.parse(
fs.readFileSync(path.join(__dirname, "..", "cdk.context.json"), "utf8"),
) as Record<string, unknown>;
const app = new cdk.App({ context });
const stack = new FileShareStack(app, "TestFileShare", {
env: { account: "328440206208", region: "us-east-1" },
});
const template = Template.fromStack(stack);
describe("FileShareStack security group", () => {
it("allows SMB, FileBrowser, and SFTP from the office VPN", () => {
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
GroupName: "file-share",
SecurityGroupIngress: Match.arrayWith([
Match.objectLike({
CidrIp: "10.10.0.0/16",
FromPort: 445,
ToPort: 445,
IpProtocol: "tcp",
}),
Match.objectLike({
CidrIp: "10.10.0.0/16",
FromPort: 8080,
ToPort: 8080,
IpProtocol: "tcp",
}),
Match.objectLike({
CidrIp: "10.10.0.0/16",
FromPort: 22,
ToPort: 22,
IpProtocol: "tcp",
}),
]),
});
});
it("allows SMB and FileBrowser from the VPC CIDR", () => {
template.hasResourceProperties("AWS::EC2::SecurityGroup", {
SecurityGroupIngress: Match.arrayWith([
Match.objectLike({
CidrIp: "10.20.0.0/16",
FromPort: 445,
ToPort: 445,
IpProtocol: "tcp",
}),
Match.objectLike({
CidrIp: "10.20.0.0/16",
FromPort: 8080,
ToPort: 8080,
IpProtocol: "tcp",
}),
]),
});
});
});
describe("FileShareStack instance IAM", () => {
it("attaches AmazonSSMManagedInstanceCore to the instance role", () => {
template.hasResourceProperties("AWS::IAM::Role", {
RoleName: "file-share-instance",
ManagedPolicyArns: Match.arrayWith([
Match.objectLike({
"Fn::Join": Match.arrayWith([
Match.arrayWith([
Match.stringLikeRegexp("AmazonSSMManagedInstanceCore"),
]),
]),
}),
]),
});
});
it("scopes Secrets Manager GetSecretValue to file-share/*", () => {
template.hasResourceProperties("AWS::IAM::Policy", {
PolicyDocument: {
Statement: Match.arrayWith([
Match.objectLike({
Action: "secretsmanager:GetSecretValue",
Effect: "Allow",
Resource:
"arn:aws:secretsmanager:us-east-1:328440206208:secret:file-share/*",
}),
]),
},
});
});
});
describe("FileShareStack instance", () => {
it("uses t4g.small with an encrypted root volume", () => {
template.hasResourceProperties("AWS::EC2::Instance", {
InstanceType: "t4g.small",
BlockDeviceMappings: Match.arrayWith([
Match.objectLike({
DeviceName: "/dev/xvda",
Ebs: Match.objectLike({
Encrypted: true,
VolumeType: "gp3",
}),
}),
]),
});
});
});
describe("FileShareStack DLM and data volume", () => {
it("enables the nightly snapshot lifecycle policy", () => {
template.hasResourceProperties("AWS::DLM::LifecyclePolicy", {
State: "ENABLED",
Description: "Nightly EBS snapshots for file share data volume",
});
});
it("attaches the imported data volume by ID", () => {
template.hasResourceProperties("AWS::EC2::VolumeAttachment", {
VolumeId: "vol-04d951cccacc435b5",
Device: "/dev/xvdf",
});
});
});

View file

@ -20,5 +20,5 @@
"resolveJsonModule": true,
"esModuleInterop": true
},
"exclude": ["node_modules", "cdk.out"]
"exclude": ["node_modules", "cdk.out", "test"]
}