mirror of
https://github.com/Sea-Haven-Industries/payments-dashboard.git
synced 2026-10-02 06:13:25 +00:00
* refactor(iam): forget in-repo HCP exec roles Org-baseline owns the apply and plan roles, so this workspace can assume them without a bootstrap window. Prod state forgets the old addresses without destroying the live roles. * ci(terraform): pin the isolation check to v1.0.21 The pre-release pin cloned the private .github repo with the caller token and the Terraform job failed. v1.0.21 loads the checker from the workflow commit.
72 lines
1.6 KiB
YAML
72 lines
1.6 KiB
YAML
name: CI
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
test:
|
|
name: Test
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
|
|
- name: Install
|
|
run: npm ci
|
|
|
|
- name: Test
|
|
run: npm test
|
|
|
|
terraform:
|
|
name: Terraform
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-terraform.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
|
|
with:
|
|
terraform-version: "1.16.0"
|
|
working-directory: terraform
|
|
app-paths: |
|
|
src/
|
|
package.json
|
|
package-lock.json
|
|
|
|
ci:
|
|
name: ci / ci
|
|
needs: [test, terraform]
|
|
if: ${{ always() && !cancelled() }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Check jobs
|
|
env:
|
|
TEST_RESULT: ${{ needs.test.result }}
|
|
TERRAFORM_RESULT: ${{ needs.terraform.result }}
|
|
run: |
|
|
set -euo pipefail
|
|
fail=0
|
|
check() {
|
|
local name="$1"
|
|
local result="$2"
|
|
case "${result}" in
|
|
success)
|
|
echo "${name}: ${result}"
|
|
;;
|
|
*)
|
|
echo "${name}: ${result}" >&2
|
|
fail=1
|
|
;;
|
|
esac
|
|
}
|
|
check test "${TEST_RESULT}"
|
|
check terraform "${TERRAFORM_RESULT}"
|
|
exit "${fail}"
|