#!/usr/bin/env python3 """Guard seahaven-dev-only Terraform and deploy workflows (AP-9/10/11).""" from pathlib import Path ROOT = Path(__file__).resolve().parents[1] def test_no_hcp_iam_and_no_prod(): tf_dir = ROOT / "terraform" assert not (tf_dir / "hcp_iam.tf").exists() assert not (tf_dir / "acm.tf").exists() joined = "\n".join(p.read_text() for p in sorted(tf_dir.glob("*.tf"))) for needle in ( "environment:prod", "seahaven-ap-prod", "seahaven-prod", "ap.seahaven.com", "011934824531", "afterhours", "hcptf-bootstrap", 'contains(["dev", "prod"]', ): assert needle not in joined, needle variables = (tf_dir / "variables.tf").read_text() assert 'var.environment == "dev"' in variables locals_tf = (tf_dir / "locals.tf").read_text() assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf ecs = (tf_dir / "ecs.tf").read_text() assert "ignore_changes = [container_definitions]" in ecs assert "ignore_changes = [task_definition, desired_count]" in ecs assert 'path = "/api/health"' in ecs assert "public.ecr.aws/docker/library/node:24-alpine" in ecs assert 'tagStatus = "untagged"' in ecs assert 'tagStatus = "any"' not in ecs cloudfront = (tf_dir / "cloudfront.tf").read_text() assert "cloudfront_default_certificate = true" in cloudfront assert "aliases" not in cloudfront alarms = (tf_dir / "alarms.tf").read_text() assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2 assert "insufficient_data_actions" not in alarms assert "ok_actions" not in alarms locals_tf = (tf_dir / "locals.tf").read_text() assert ( 'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"' in locals_tf ) cognito = (tf_dir / "cognito.tf").read_text() assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito assert '"ALLOW_USER_SRP_AUTH"' in cognito assert "aws_secretsmanager_secret_version.google_oidc" in cognito assert 'local.google_oidc_client_id != "replace-me"' in cognito assert 'local.google_oidc_client_secret != "replace-me"' in cognito readme = (ROOT / "README.md").read_text() assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme assert "Those runs fail on purpose until both exist." in readme secrets = (tf_dir / "secrets.tf").read_text() assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets assert "ignore_changes = [secret_string]" in secrets github = (tf_dir / "iam_github_deploy.tf").read_text() assert "environment:dev" in github assert "environment:prod" not in github assert "refs/tags/" not in github assert "deploy-web.yaml@refs/heads/" in github assert "deploy-api.yaml@refs/heads/" in github def test_deploy_workflows_are_dev_only(): for name in ("deploy-web.yaml", "deploy-api.yaml"): text = (ROOT / ".github" / "workflows" / name).read_text() assert "release:" not in text assert "options: [dev]" in text assert "options: [dev, prod]" not in text assert "environment:prod" not in text assert "cancel-in-progress: false" in text assert "environment: ${{ needs.target.outputs.environment }}" in text assert "DEPLOY_ROLE_ARN is empty" in text assert "does not exist yet. Apply the seahaven-ap-dev workspace" in text web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text() assert "vite build" not in web assert "placeholder/" in web assert "npm run build" not in web api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text() assert "/seahaven-ap/deploy/" in api assert "GIT_SHA" in api assert "verify-api-health.sh" in api assert "packages/api/dist/db/migrate.js" in api assert "DEV_AUTH_BYPASS" in api assert '\\"value\\":\\"false\\"' in api if __name__ == "__main__": test_no_hcp_iam_and_no_prod() test_deploy_workflows_are_dev_only() print("PASS: seahaven-dev terraform and deploy workflow guards")