mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 11:13:12 +00:00
* ci: convert onto org HCP reusables Switch Fargate CD and CI to the v1.0.13 org workflows, emit ci-complete, and retarget githubdeploy OIDC to the reusable plus the thin caller. * chore(security): retarget githubdeploy Checkov suppression The OIDC dual-claim edit shifted CKV_AWS_111 from line 40 to 49. Permissions are unchanged. * style: apply formatter * ci: pin org reusables to v1.0.14 Drop collect-only and requirements from the python lint caller now that ci-python-app is lint-only. * test(ci): probe autofix with a ruff format violation * style: apply formatter --------- Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
40 lines
1.3 KiB
Python
40 lines
1.3 KiB
Python
"""Sentry DSN is an SSM SecureString; the task receives the parameter name."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
TERRAFORM = ROOT / "terraform"
|
|
|
|
|
|
def _read(name: str) -> str:
|
|
return (TERRAFORM / name).read_text()
|
|
|
|
|
|
def test_sentry_dsn_is_secure_string_stub():
|
|
ssm_tf = _read("ssm.tf")
|
|
assert 'resource "aws_ssm_parameter" "sentry_dsn"' in ssm_tf
|
|
assert 'name = "${local.ssm_prefix}/sentry-dsn"' in ssm_tf
|
|
assert 'type = "SecureString"' in ssm_tf
|
|
assert 'value = "unset"' in ssm_tf
|
|
assert "ignore_changes = [value]" in ssm_tf
|
|
assert 'data "aws_ssm_parameter" "sentry_dsn_value"' not in ssm_tf
|
|
|
|
|
|
def test_ecs_task_receives_sentry_dsn_parameter_name():
|
|
ecs_tf = _read("ecs.tf")
|
|
assert ecs_tf.count("SENTRY_DSN_PARAM") == 1
|
|
assert "aws_ssm_parameter.sentry_dsn.name" in ecs_tf
|
|
assert "SENTRY_DSN " not in ecs_tf
|
|
|
|
|
|
def test_terraform_does_not_embed_a_sentry_dsn():
|
|
for path in TERRAFORM.glob("*.tf"):
|
|
text = path.read_text()
|
|
assert "ingest.sentry.io" not in text
|
|
assert "SENTRY_DSN =" not in text
|
|
|
|
|
|
def test_deploy_api_injects_sentry_dsn_param():
|
|
workflow = (ROOT / ".github/workflows/deploy-api.yaml").read_text()
|
|
assert "extra-task-env:" in workflow
|
|
assert '"SENTRY_DSN_PARAM":"/meal-order-manager/sentry-dsn"' in workflow
|