payments-dashboard/.github/workflows/ci.yaml
Adam Moussa 7c2c806339
Some checks are pending
Deploy / Deploy to dev (push) Waiting to run
Deploy / Deploy to prod (push) Waiting to run
refactor(iam): forget in-repo HCP exec roles (#120)
* refactor(iam): forget in-repo HCP exec roles

Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles.

* ci(terraform): pin the isolation check to v1.0.21

The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
2026-10-01 21:29:22 -04:00

72 lines
1.6 KiB
YAML

name: CI
on:
pull_request:
branches: [main]
merge_group:
permissions:
contents: read
jobs:
test:
name: Test
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
cache: npm
- name: Install
run: npm ci
- name: Test
run: npm test
terraform:
name: Terraform
uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
with:
terraform-version: "1.16.0"
working-directory: terraform
app-paths: |
src/
package.json
package-lock.json
ci:
name: ci / ci
needs: [test, terraform]
if: ${{ always() && !cancelled() }}
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Check jobs
env:
TEST_RESULT: ${{ needs.test.result }}
TERRAFORM_RESULT: ${{ needs.terraform.result }}
run: |
set -euo pipefail
fail=0
check() {
local name="$1"
local result="$2"
case "${result}" in
success)
echo "${name}: ${result}"
;;
*)
echo "${name}: ${result}" >&2
fail=1
;;
esac
}
check test "${TEST_RESULT}"
check terraform "${TERRAFORM_RESULT}"
exit "${fail}"