meal-order-manager/tests/test_terraform_vpc.py

46 lines
1.7 KiB
Python
Raw Normal View History

"""Meals creates a VPC unless existing_vpc_id is set (prod shares afterhours)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
TERRAFORM = ROOT / "terraform"
def _read(name: str) -> str:
return (TERRAFORM / name).read_text()
def test_meals_owns_a_vpc_instead_of_looking_up_default():
vpc = _read("vpc.tf")
ecs = _read("ecs.tf")
locals_tf = _read("locals.tf")
variables = _read("variables.tf")
data = _read("data.tf")
assert 'resource "aws_vpc" "this"' in vpc
assert "count = local.manage_vpc ? 1 : 0" in vpc
assert 'variable "existing_vpc_id"' in variables
assert 'variable "existing_public_subnet_ids"' in variables
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
assert (
'manage_vpc = var.existing_vpc_id == "" && !local.is_prod' in locals_tf
)
assert 'data "aws_vpc" "default"' not in ecs
assert "data.aws_vpc.default" not in ecs
assert "data.aws_subnets.default" not in ecs
assert "vpc_id = local.vpc_id" in ecs
assert "subnets = local.public_subnet_ids" in ecs
assert "subnets = local.public_subnet_ids" in ecs
assert "ec2:CreateVpc" in _read("hcp_iam.tf")
assert 'check "existing_vpc_pair"' in data
assert 'check "existing_subnets_in_vpc"' in data
assert "from = aws_vpc.this" in vpc
assert "to = aws_vpc.this[0]" in vpc
feat(api): add OpenAPI Redocly contract and VPC outputs (DEV-289) (#206) * feat(infra): export attached VPC ids and lock prod to afterhours (DEV-289) Prod must keep existing_vpc_id pointed at the afterhours VPC. Outputs expose the resolved vpc_id and public subnet IDs. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * feat(api): add OpenAPI 3.1 and Redocly lint in CI (DEV-289) Same extends: recommended ruleset and @redocly/cli 2.52.1 as internal-portal. Documents current { error: string } JSON errors. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): document 4xx and reject invalid form-status weeks (DEV-289) Health, form-status, and roster document 400. form-status now maps current and returns 400 for a week that is not current or YYYY-WNN. Redocly treats 302 as a success response, matching the portal. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * style(test): format VPC contract assertions for ruff (DEV-289) Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): fail Redocly on missing 4xx and 2xx/3xx (DEV-289) Promote operation-4xx-response and the 2xx-or-3xx success rule to error. Replace unused health and roster 400s with 403, matching portal health. Form-status keeps its real 400 for invalid week. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(api): split week params and allow live menu nulls (DEV-289) Menu and form-status take current or YYYY-WNN. Orders take YYYY-WNN or a calendar date and reject current. Menu payloads may emit null menu_url, calories, protein, and image_url. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> * fix(infra): fail prod apply without the afterhours VPC (DEV-289) Prod never creates the 10.60 fallback VPC. A terraform_data precondition fails plan and apply when existing_vpc_id is empty, instead of a check block that only warns. Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:33:48 +00:00
outputs = _read("outputs.tf")
assert 'output "vpc_id"' in outputs
assert "value = local.vpc_id" in outputs
assert 'output "public_subnet_ids"' in outputs
assert 'check "prod_reuses_afterhours_vpc"' in data
assert "prod_requires_afterhours_vpc" in vpc
assert "Do not mint 10.60." in vpc
assert 'count = var.existing_vpc_id == "" ? 0 : 1' in vpc