#!/usr/bin/env python3 """Small deterministic tests for check-terraform-import-plan.py.""" from __future__ import annotations import json import subprocess import sys import tempfile from pathlib import Path SCRIPT = Path(__file__).with_name("check-terraform-import-plan.py") def run_case(actions: list[str], *, allow_update: bool = False) -> subprocess.CompletedProcess[str]: plan = { "resource_changes": [ { "address": "module.deploy_role.aws_iam_role.github_deploy", "mode": "managed", "type": "aws_iam_role", "change": {"actions": actions}, } ] } with tempfile.TemporaryDirectory() as directory: plan_path = Path(directory) / "plan.json" plan_path.write_text(json.dumps(plan), encoding="utf-8") command = [sys.executable, str(SCRIPT), str(plan_path)] if allow_update: command.append("--allow-update") return subprocess.run(command, check=False, capture_output=True, text=True) def main() -> int: cases = [ ("no-op import", run_case(["no-op"]), 0), ("initial update", run_case(["update"]), 1), ("controlled update", run_case(["update"], allow_update=True), 0), ("create", run_case(["create"]), 1), ("replacement", run_case(["delete", "create"]), 1), ("destroy", run_case(["delete"]), 1), ] failures = [ (name, result, expected) for name, result, expected in cases if result.returncode != expected ] if failures: print( "FAIL: plan-check cases failed: " + ", ".join(name for name, _, _ in failures), file=sys.stderr, ) for name, result, expected in failures: print( f"{name}: expected {expected}, got {result.returncode}\n" f"{result.stdout}{result.stderr}", file=sys.stderr, ) return 1 print("PASS: Terraform import plan safety checks") return 0 if __name__ == "__main__": raise SystemExit(main())