meal-order-manager/.github/workflows/build-layer.yml
Adam Moussa 40ea4ed898
feat(infra): migrate meal-order-manager to HCP Terraform
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
2026-08-07 19:19:51 -04:00

68 lines
2.3 KiB
YAML

name: Build Lambda Layer
# Build verification only. Terraform owns Lambda packaging: terraform/artifacts.tf
# runs terraform/build_packages.sh during plan and carries the resulting zips into
# the plan as content_base64, so there is no artifact for this workflow to upload
# and no job here holds AWS credentials.
#
# What it does check is that the layer still builds for the Lambda target
# (python3.12 / arm64) and stays small enough to travel inside a plan. boto3 and
# friends are stripped by build_packages.sh because the runtime provides them; if
# that strip ever stops working, the size guard below fails the PR rather than
# letting a multi-hundred-megabyte plan payload reach HCP Terraform.
on:
pull_request:
branches: [main]
paths:
- "src/shared/**"
- "functions/**"
- "terraform/build_packages.sh"
- "terraform/build_packages_external.sh"
- ".github/workflows/build-layer.yml"
push:
branches: [main]
paths:
- "src/shared/**"
- "functions/**"
- "terraform/build_packages.sh"
- "terraform/build_packages_external.sh"
- ".github/workflows/build-layer.yml"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: build-layer-${{ github.ref }}
cancel-in-progress: false
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-python@e797f83bcb11b83ae66e0230d6156d7c80228e7c # v6.0.0
with:
python-version: "3.12"
- name: Build packages
run: bash terraform/build_packages.sh
- name: Check layer size
run: |
set -euo pipefail
cd terraform/build/layer
zip -qrX ../packages/layer-check.zip python
BYTES=$(wc -c < ../packages/layer-check.zip)
LIMIT=$((40 * 1024 * 1024))
echo "Layer zip: $BYTES bytes (limit $LIMIT)"
if [ "$BYTES" -gt "$LIMIT" ]; then
echo "Layer exceeds the plan-payload budget. Check that build_packages.sh still strips the runtime-provided packages." >&2
exit 1
fi
if [ -d python/boto3 ]; then
echo "boto3 is present in the layer; the runtime already provides it." >&2
exit 1
fi