meal-order-manager/tests/test_terraform_vpc.py
Cursor Agent 7bb5cb73aa
fix(infra): fail prod apply without the afterhours VPC (DEV-289)
Prod never creates the 10.60 fallback VPC. A terraform_data precondition
fails plan and apply when existing_vpc_id is empty, instead of a check
block that only warns.

Co-authored-by: Adam Moussa <amoussa1229@users.noreply.github.com>
2026-09-22 00:13:16 +00:00

45 lines
1.7 KiB
Python

"""Meals creates a VPC unless existing_vpc_id is set (prod shares afterhours)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
TERRAFORM = ROOT / "terraform"
def _read(name: str) -> str:
return (TERRAFORM / name).read_text()
def test_meals_owns_a_vpc_instead_of_looking_up_default():
vpc = _read("vpc.tf")
ecs = _read("ecs.tf")
locals_tf = _read("locals.tf")
variables = _read("variables.tf")
data = _read("data.tf")
assert 'resource "aws_vpc" "this"' in vpc
assert "count = local.manage_vpc ? 1 : 0" in vpc
assert 'variable "existing_vpc_id"' in variables
assert 'variable "existing_public_subnet_ids"' in variables
assert (
'manage_vpc = var.existing_vpc_id == "" && !local.is_prod' in locals_tf
)
assert 'data "aws_vpc" "default"' not in ecs
assert "data.aws_vpc.default" not in ecs
assert "data.aws_subnets.default" not in ecs
assert "vpc_id = local.vpc_id" in ecs
assert "subnets = local.public_subnet_ids" in ecs
assert "subnets = local.public_subnet_ids" in ecs
assert "ec2:CreateVpc" in _read("hcp_iam.tf")
assert 'check "existing_vpc_pair"' in data
assert 'check "existing_subnets_in_vpc"' in data
assert "from = aws_vpc.this" in vpc
assert "to = aws_vpc.this[0]" in vpc
outputs = _read("outputs.tf")
assert 'output "vpc_id"' in outputs
assert "value = local.vpc_id" in outputs
assert 'output "public_subnet_ids"' in outputs
assert 'check "prod_reuses_afterhours_vpc"' in data
assert "prod_requires_afterhours_vpc" in vpc
assert "Do not mint 10.60." in vpc
assert 'count = var.existing_vpc_id == "" ? 0 : 1' in vpc