"""Sentry DSN is an SSM SecureString; the task receives the parameter name.""" from pathlib import Path ROOT = Path(__file__).resolve().parents[1] TERRAFORM = ROOT / "terraform" def _read(name: str) -> str: return (TERRAFORM / name).read_text() def test_sentry_dsn_is_secure_string_stub(): ssm_tf = _read("ssm.tf") assert 'resource "aws_ssm_parameter" "sentry_dsn"' in ssm_tf assert 'name = "${local.ssm_prefix}/sentry-dsn"' in ssm_tf assert 'type = "SecureString"' in ssm_tf assert 'value = "unset"' in ssm_tf assert "ignore_changes = [value]" in ssm_tf assert 'data "aws_ssm_parameter" "sentry_dsn_value"' not in ssm_tf def test_ecs_task_receives_sentry_dsn_parameter_name(): ecs_tf = _read("ecs.tf") assert ecs_tf.count("SENTRY_DSN_PARAM") == 1 assert "aws_ssm_parameter.sentry_dsn.name" in ecs_tf assert "SENTRY_DSN " not in ecs_tf def test_terraform_does_not_embed_a_sentry_dsn(): for path in TERRAFORM.glob("*.tf"): text = path.read_text() assert "ingest.sentry.io" not in text assert "SENTRY_DSN =" not in text def test_deploy_api_injects_sentry_dsn_param(): workflow = (ROOT / ".github/workflows/deploy-api.yaml").read_text() assert "extra-task-env:" in workflow assert '"SENTRY_DSN_PARAM":"/meal-order-manager/sentry-dsn"' in workflow