seahaven-ap/scripts/test-terraform-dev-only.py

72 lines
2.8 KiB
Python
Raw Normal View History

#!/usr/bin/env python3
"""Guard seahaven-dev-only Terraform and deploy workflows (AP-9/10/11)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
def test_no_hcp_iam_and_no_prod():
tf_dir = ROOT / "terraform"
assert not (tf_dir / "hcp_iam.tf").exists()
assert not (tf_dir / "acm.tf").exists()
joined = "\n".join(p.read_text() for p in sorted(tf_dir.glob("*.tf")))
for needle in (
"environment:prod",
"seahaven-ap-prod",
"seahaven-prod",
"ap.seahaven.com",
"011934824531",
"afterhours",
"hcptf-bootstrap",
'contains(["dev", "prod"]',
):
assert needle not in joined, needle
variables = (tf_dir / "variables.tf").read_text()
assert 'var.environment == "dev"' in variables
locals_tf = (tf_dir / "locals.tf").read_text()
assert 'vpc_cidr' in locals_tf and "10.63.0.0/16" in locals_tf
assert 'hcp_workspace' in locals_tf and "seahaven-ap-dev" in locals_tf
ecs = (tf_dir / "ecs.tf").read_text()
assert "ignore_changes = [container_definitions]" in ecs
assert "ignore_changes = [task_definition, desired_count]" in ecs
assert 'path = "/api/health"' in ecs
assert "public.ecr.aws/docker/library/node:24-alpine" in ecs
cloudfront = (tf_dir / "cloudfront.tf").read_text()
assert "cloudfront_default_certificate = true" in cloudfront
assert "aliases" not in cloudfront
github = (tf_dir / "iam_github_deploy.tf").read_text()
assert "environment:dev" in github
assert "environment:prod" not in github
assert "refs/tags/" not in github
assert "deploy-web.yaml@refs/heads/" in github
assert "deploy-api.yaml@refs/heads/" in github
def test_deploy_workflows_are_dev_only():
for name in ("deploy-web.yaml", "deploy-api.yaml"):
text = (ROOT / ".github" / "workflows" / name).read_text()
assert "release:" not in text
assert "options: [dev]" in text
assert "options: [dev, prod]" not in text
assert "environment:prod" not in text
assert "cancel-in-progress: false" in text
assert "environment: ${{ needs.target.outputs.environment }}" in text
web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text()
assert "vite build" not in web
assert "placeholder/" in web
assert "npm run build" not in web
api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text()
assert "/seahaven-ap/deploy/" in api
assert "GIT_SHA" in api
assert "verify-api-health.sh" in api
assert "packages/api/dist/db/migrate.js" in api
assert "DEV_AUTH_BYPASS" in api
assert '\\"value\\":\\"false\\"' in api
if __name__ == "__main__":
test_no_hcp_iam_and_no_prod()
test_deploy_workflows_are_dev_only()
print("PASS: seahaven-dev terraform and deploy workflow guards")