name: CI # Converted HCP caller. ci-complete aggregates the portions. The CDK job id # stays `ci` so the org "main branch protection" ruleset still sees `ci / ci` # until this repo is moved onto "CI complete". on: pull_request: branches: [main, hotfix/**, release/**] merge_group: push: branches: [hotfix/**, release/**] permissions: contents: read jobs: autofix: if: github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork uses: Sea-Haven-Industries/.github/.github/workflows/ci-autofix.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85 # v1.0.20 permissions: contents: write secrets: inherit with: presets: terraform terraform-version: "1.16.0" ci: needs: autofix if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true') uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85 # v1.0.20 with: node-version: "24" enable-qemu: true terraform: needs: autofix if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true') uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@ee5b843ca105422b679c3fdeb9eaa68c6e500a85 # v1.0.20 with: terraform-version: "1.16.0" ci-complete: name: ci-complete needs: [autofix, ci, terraform] if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true') runs-on: ubuntu-latest timeout-minutes: 5 steps: - name: Require portions env: CI: ${{ needs.ci.result }} TERRAFORM: ${{ needs.terraform.result }} run: | set -euo pipefail test "${CI}" = success test "${TERRAFORM}" = success