seahaven-ap/scripts/test-terraform-dev-only.py

89 lines
3.7 KiB
Python
Executable file

#!/usr/bin/env python3
"""Guard seahaven-dev-only Terraform and deploy workflows (AP-9/10/11)."""
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
def test_no_hcp_iam_and_no_prod():
tf_dir = ROOT / "terraform"
assert not (tf_dir / "hcp_iam.tf").exists()
assert not (tf_dir / "acm.tf").exists()
joined = "\n".join(p.read_text() for p in sorted(tf_dir.glob("*.tf")))
for needle in (
"environment:prod",
"seahaven-ap-prod",
"seahaven-prod",
"ap.seahaven.com",
"011934824531",
"afterhours",
"hcptf-bootstrap",
'contains(["dev", "prod"]',
):
assert needle not in joined, needle
variables = (tf_dir / "variables.tf").read_text()
assert 'var.environment == "dev"' in variables
locals_tf = (tf_dir / "locals.tf").read_text()
assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf
assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf
ecs = (tf_dir / "ecs.tf").read_text()
assert "ignore_changes = [container_definitions]" in ecs
assert "ignore_changes = [task_definition, desired_count]" in ecs
assert 'path = "/api/health"' in ecs
assert "public.ecr.aws/docker/library/node:24-alpine" in ecs
assert 'tagStatus = "untagged"' in ecs
assert 'tagStatus = "any"' not in ecs
cloudfront = (tf_dir / "cloudfront.tf").read_text()
assert "cloudfront_default_certificate = true" in cloudfront
assert "aliases" not in cloudfront
alarms = (tf_dir / "alarms.tf").read_text()
assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2
assert "insufficient_data_actions" not in alarms
assert "ok_actions" not in alarms
locals_tf = (tf_dir / "locals.tf").read_text()
assert (
'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"'
in locals_tf
)
cognito = (tf_dir / "cognito.tf").read_text()
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
assert '"ALLOW_USER_SRP_AUTH"' in cognito
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
secrets = (tf_dir / "secrets.tf").read_text()
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
assert "ignore_changes = [secret_string]" in secrets
github = (tf_dir / "iam_github_deploy.tf").read_text()
assert "environment:dev" in github
assert "environment:prod" not in github
assert "refs/tags/" not in github
assert "deploy-web.yaml@refs/heads/" in github
assert "deploy-api.yaml@refs/heads/" in github
def test_deploy_workflows_are_dev_only():
for name in ("deploy-web.yaml", "deploy-api.yaml"):
text = (ROOT / ".github" / "workflows" / name).read_text()
assert "release:" not in text
assert "options: [dev]" in text
assert "options: [dev, prod]" not in text
assert "environment:prod" not in text
assert "cancel-in-progress: false" in text
assert "environment: ${{ needs.target.outputs.environment }}" in text
web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text()
assert "vite build" not in web
assert "placeholder/" in web
assert "npm run build" not in web
api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text()
assert "/seahaven-ap/deploy/" in api
assert "GIT_SHA" in api
assert "verify-api-health.sh" in api
assert "packages/api/dist/db/migrate.js" in api
assert "DEV_AUTH_BYPASS" in api
assert '\\"value\\":\\"false\\"' in api
if __name__ == "__main__":
test_no_hcp_iam_and_no_prod()
test_deploy_workflows_are_dev_only()
print("PASS: seahaven-dev terraform and deploy workflow guards")