mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-09-30 07:43:12 +00:00
Replace the mgmt SAM stack with a prod-only HCP workspace using the afterhours stub-plus-zip-CD seam so GitHub Actions owns function code and Terraform owns infrastructure.
87 lines
2 KiB
YAML
87 lines
2 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
test:
|
|
name: Test
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
|
|
- name: Install
|
|
run: npm ci
|
|
|
|
- name: Test
|
|
run: npm test
|
|
|
|
terraform:
|
|
name: Terraform
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
defaults:
|
|
run:
|
|
working-directory: terraform
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
|
|
with:
|
|
terraform_version: "1.16.0"
|
|
terraform_wrapper: false
|
|
|
|
- name: Terraform fmt
|
|
run: terraform fmt -check -recursive
|
|
|
|
- name: Terraform init
|
|
run: terraform init -backend=false
|
|
|
|
- name: Terraform validate
|
|
run: terraform validate
|
|
|
|
ci:
|
|
name: ci / ci
|
|
needs: [test, terraform]
|
|
if: ${{ always() && !cancelled() }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Check jobs
|
|
env:
|
|
TEST_RESULT: ${{ needs.test.result }}
|
|
TERRAFORM_RESULT: ${{ needs.terraform.result }}
|
|
run: |
|
|
set -euo pipefail
|
|
fail=0
|
|
check() {
|
|
local name="$1"
|
|
local result="$2"
|
|
case "${result}" in
|
|
success)
|
|
echo "${name}: ${result}"
|
|
;;
|
|
*)
|
|
echo "${name}: ${result}" >&2
|
|
fail=1
|
|
;;
|
|
esac
|
|
}
|
|
check test "${TEST_RESULT}"
|
|
check terraform "${TERRAFORM_RESULT}"
|
|
exit "${fail}"
|