mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 10:23:17 +00:00
96 lines
4.2 KiB
Python
Executable file
96 lines
4.2 KiB
Python
Executable file
#!/usr/bin/env python3
|
|
"""Guard seahaven-dev-only Terraform and deploy workflows (AP-9/10/11)."""
|
|
|
|
from pathlib import Path
|
|
|
|
ROOT = Path(__file__).resolve().parents[1]
|
|
|
|
|
|
def test_no_hcp_iam_and_no_prod():
|
|
tf_dir = ROOT / "terraform"
|
|
assert not (tf_dir / "hcp_iam.tf").exists()
|
|
assert not (tf_dir / "acm.tf").exists()
|
|
joined = "\n".join(p.read_text() for p in sorted(tf_dir.glob("*.tf")))
|
|
for needle in (
|
|
"environment:prod",
|
|
"seahaven-ap-prod",
|
|
"seahaven-prod",
|
|
"ap.seahaven.com",
|
|
"011934824531",
|
|
"afterhours",
|
|
"hcptf-bootstrap",
|
|
'contains(["dev", "prod"]',
|
|
):
|
|
assert needle not in joined, needle
|
|
variables = (tf_dir / "variables.tf").read_text()
|
|
assert 'var.environment == "dev"' in variables
|
|
locals_tf = (tf_dir / "locals.tf").read_text()
|
|
assert "vpc_cidr" in locals_tf and "10.63.0.0/16" in locals_tf
|
|
assert "hcp_workspace" in locals_tf and "seahaven-ap-dev" in locals_tf
|
|
ecs = (tf_dir / "ecs.tf").read_text()
|
|
assert "ignore_changes = [container_definitions]" in ecs
|
|
assert "ignore_changes = [task_definition, desired_count]" in ecs
|
|
assert 'path = "/api/health"' in ecs
|
|
assert "public.ecr.aws/docker/library/node:24-alpine" in ecs
|
|
assert 'tagStatus = "untagged"' in ecs
|
|
assert 'tagStatus = "any"' not in ecs
|
|
cloudfront = (tf_dir / "cloudfront.tf").read_text()
|
|
assert "cloudfront_default_certificate = true" in cloudfront
|
|
assert "aliases" not in cloudfront
|
|
alarms = (tf_dir / "alarms.tf").read_text()
|
|
assert alarms.count("alarm_actions = [local.site_alerts_arn]") == 2
|
|
assert "insufficient_data_actions" not in alarms
|
|
assert "ok_actions" not in alarms
|
|
locals_tf = (tf_dir / "locals.tf").read_text()
|
|
assert (
|
|
'site_alerts_arn = "arn:aws:sns:${var.aws_region}:${local.account_id}:site-alerts"'
|
|
in locals_tf
|
|
)
|
|
cognito = (tf_dir / "cognito.tf").read_text()
|
|
assert 'supported_identity_providers = ["COGNITO", "Google"]' in cognito
|
|
assert '"ALLOW_USER_SRP_AUTH"' in cognito
|
|
assert "aws_secretsmanager_secret_version.google_oidc" in cognito
|
|
assert 'local.google_oidc_client_id != "replace-me"' in cognito
|
|
assert 'local.google_oidc_client_secret != "replace-me"' in cognito
|
|
readme = (ROOT / "README.md").read_text()
|
|
assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme
|
|
assert "Those runs fail on purpose until both exist." in readme
|
|
secrets = (tf_dir / "secrets.tf").read_text()
|
|
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
|
|
assert "ignore_changes = [secret_string]" in secrets
|
|
github = (tf_dir / "iam_github_deploy.tf").read_text()
|
|
assert "environment:dev" in github
|
|
assert "environment:prod" not in github
|
|
assert "refs/tags/" not in github
|
|
assert "deploy-web.yaml@refs/heads/" in github
|
|
assert "deploy-api.yaml@refs/heads/" in github
|
|
|
|
|
|
def test_deploy_workflows_are_dev_only():
|
|
for name in ("deploy-web.yaml", "deploy-api.yaml"):
|
|
text = (ROOT / ".github" / "workflows" / name).read_text()
|
|
assert "release:" not in text
|
|
assert "options: [dev]" in text
|
|
assert "options: [dev, prod]" not in text
|
|
assert "environment:prod" not in text
|
|
assert "cancel-in-progress: false" in text
|
|
assert "environment: ${{ needs.target.outputs.environment }}" in text
|
|
assert "DEPLOY_ROLE_ARN is empty" in text
|
|
assert "does not exist yet. Apply the seahaven-ap-dev workspace" in text
|
|
web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text()
|
|
assert "vite build" not in web
|
|
assert "placeholder/" in web
|
|
assert "npm run build" not in web
|
|
api = (ROOT / ".github" / "workflows" / "deploy-api.yaml").read_text()
|
|
assert "/seahaven-ap/deploy/" in api
|
|
assert "GIT_SHA" in api
|
|
assert "verify-api-health.sh" in api
|
|
assert "packages/api/dist/db/migrate.js" in api
|
|
assert "DEV_AUTH_BYPASS" in api
|
|
assert '\\"value\\":\\"false\\"' in api
|
|
|
|
|
|
if __name__ == "__main__":
|
|
test_no_hcp_iam_and_no_prod()
|
|
test_deploy_workflows_are_dev_only()
|
|
print("PASS: seahaven-dev terraform and deploy workflow guards")
|