meal-order-manager/.github/workflows/ci.yml
Adam Moussa f632020b20
Some checks are pending
Deploy API / Deploy API to dev (push) Waiting to run
Deploy API / Deploy API to prod (push) Waiting to run
ci: convert onto org HCP reusables (PLAT-222) (#214)
* ci: convert onto org HCP reusables

Switch Fargate CD and CI to the v1.0.13 org workflows, emit ci-complete, and retarget githubdeploy OIDC to the reusable plus the thin caller.

* chore(security): retarget githubdeploy Checkov suppression

The OIDC dual-claim edit shifted CKV_AWS_111 from line 40 to 49. Permissions are unchanged.

* style: apply formatter

* ci: pin org reusables to v1.0.14

Drop collect-only and requirements from the python lint caller now that ci-python-app is lint-only.

* test(ci): probe autofix with a ruff format violation

* style: apply formatter

---------

Co-authored-by: sea-haven-auto-fix[bot] <5037331+sea-haven-auto-fix[bot]@users.noreply.github.com>
2026-09-22 20:01:17 +00:00

110 lines
3.5 KiB
YAML

name: CI
on:
pull_request:
branches: [main, hotfix/**, release/**]
merge_group:
push:
branches: [hotfix/**, release/**]
permissions:
contents: read
jobs:
autofix:
if: github.event_name == 'pull_request' && !github.event.pull_request.head.repo.fork
uses: Sea-Haven-Industries/.github/.github/workflows/ci-autofix.yaml@fd4113241058d4709f80d5c29f7d5c43030ae6fa # v1.0.14
permissions:
contents: write
secrets: inherit
with:
format-command: ruff format .
lint-fix-command: ruff check --fix .
extra-command: terraform fmt -recursive terraform
terraform-version: "1.9.8"
lint:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-app.yaml@fd4113241058d4709f80d5c29f7d5c43030ae6fa # v1.0.14
with:
python-version: "3.12.14"
template-js:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1.x
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24.19.0"
cache: npm
- name: Install JavaScript tooling
run: npm ci
- name: Check template JavaScript
run: npm run check:templates
- name: Lint OpenAPI
run: npm run openapi:lint
test:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1.x
with:
persist-credentials: false
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.x
with:
python-version: "3.12.14"
- name: Install Python dependencies
shell: bash
run: |
pip install pytest
pip install -r requirements-api.txt
while IFS= read -r -d '' req; do
pip install -r "$req"
done < <(find . -name requirements.txt -not -path './.aws-sam/*' -print0)
- name: Install Playwright Chromium
run: playwright install --with-deps chromium
- name: Run tests
run: pytest
terraform:
needs: autofix
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@fd4113241058d4709f80d5c29f7d5c43030ae6fa # v1.0.14
with:
terraform-version: "1.9.8"
ci-complete:
name: ci-complete
needs: [autofix, lint, template-js, test, terraform]
if: always() && !cancelled() && (needs.autofix.result == 'skipped' || needs.autofix.outputs.committed != 'true')
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Require portions
env:
LINT: ${{ needs.lint.result }}
TEMPLATE_JS: ${{ needs.template-js.result }}
TEST: ${{ needs.test.result }}
TERRAFORM: ${{ needs.terraform.result }}
run: |
set -euo pipefail
test "${LINT}" = success
test "${TEMPLATE_JS}" = success
test "${TEST}" = success
test "${TERRAFORM}" = success