name: Terraform CI # Static checks only. Plans run in HCP Terraform as speculative VCS runs on the # PR (shoc-backend-dev and shoc-backend-staging). Applies are HCP auto-apply # on merge to main (dev) and on a vX.Y.Z-staging tag (staging). on: pull_request: branches: [main, dev] paths: - "terraform/**" - "scripts/**" - ".github/workflows/ci-terraform.yaml" - ".github/workflows/deploy.yaml" - ".github/workflows/deploy-tag.yaml" - ".github/workflows/release.yaml" push: branches: [main] paths: - "terraform/**" - "scripts/**" - ".github/workflows/ci-terraform.yaml" permissions: contents: read jobs: terraform: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1 with: terraform_version: "1.9.8" terraform_wrapper: false - name: Terraform fmt run: terraform fmt -check -recursive terraform - name: Validate live/dev run: | terraform -chdir=terraform/live/dev init -backend=false terraform -chdir=terraform/live/dev validate - name: Validate live/staging run: | terraform -chdir=terraform/live/staging init -backend=false terraform -chdir=terraform/live/staging validate - name: Import plan guard tests run: python3 scripts/test-terraform-import-plan-check.py - name: Release promotion script tests run: | python3 scripts/test_next_release_tag.py python3 scripts/test_require_commit_checks.py python3 scripts/test_check_app_terraform_isolation.py