The dev Terraform rollback verify was the one gate the previous commit
missed, and it is the copy that actually ran on 34293894914. It still
decided on the first Ready poll: previous version correctly restored,
health not yet converged, reported as a failed rollback.
Split the version and health conditions the same way the other three
gates now do — a Ready poll on the wrong version fails immediately and
names the version that came up, while the correct version with unsettled
health keeps polling inside the unchanged 80 x 15s budget. Timeout now
reports the last observed status, version and health.
Elastic Beanstalk reports Ready as soon as a rollout finishes, before
enhanced health has converged. Both verification gates decided on the first
Ready poll, so a release whose version had activated correctly was failed on
a health value that had not settled yet — and then rolled back.
The failure message compounded it: run 34293894914 printed 'Environment
became Ready without activating expected version a0fdd199...' when the
active version was exactly a0fdd199... The discriminator was health, not
version, which sends whoever reads the log after the wrong problem.
Separate the two conditions, keep polling while the correct version is
active but health has not settled, and report the last observed state on
timeout. An environment that stays unhealthy for the full window still
fails; this does not widen what counts as a good deploy.
* feat(deploy): move dev application CD through Terraform
GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.
* fix: add permissions block for dependency-review workflow
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* fix(terraform): stop pinning the generated dev instance SG
---------
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
* feat(terraform): add safe backend environment adoption
Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.
* ci(deploy): pause dev and staging deployments
Prevent application releases from racing Terraform adoption while retaining production deployment and validation.
* ci(deploy): require manual environment dispatch
* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`
The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.
CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding
* chore(deps): add `terraform` to renovate dependency coverage
* ci(deploy): drop unprovisioned prod dispatch path
* chore(renovate): add Renovate frontend overlay config
* chore: remove dependabot.yml config
* fix: add `github-actions` to `enabledManagers`
With the removal of this repositories `dependabot.yml`, a lack of `github-actions` within the config would leave a coverage gap on `actions/checkout`, `actions/setup-dotnet`, `actions/setup-node`, etc.
* fix(renovate): annotate pinned actions
---------
Co-authored-by: Alexandre Brandizzi <alex_brandizzi@hotmail.com>