shoc-backend/.github/workflows/ci-terraform.yaml
Adam Moussa 8f4fa36647
refactor(cd): ship Elastic Beanstalk versions from GitHub on main
Keep application and Terraform changes in separate PRs so a merge cannot race an HCP apply against an app deploy.
2026-09-17 15:54:31 -04:00

60 lines
1.8 KiB
YAML

name: Terraform CI
# Static checks only. Plans run in HCP Terraform as speculative VCS runs on the
# PR (shoc-backend-dev and shoc-backend-staging). Applies are HCP auto-apply
# on merge to main (dev) and on a vX.Y.Z-staging tag (staging).
on:
pull_request:
branches: [main, dev]
paths:
- "terraform/**"
- "scripts/**"
- ".github/workflows/ci-terraform.yaml"
- ".github/workflows/deploy.yaml"
- ".github/workflows/deploy-tag.yaml"
- ".github/workflows/release.yaml"
push:
branches: [main]
paths:
- "terraform/**"
- "scripts/**"
- ".github/workflows/ci-terraform.yaml"
permissions:
contents: read
jobs:
terraform:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
with:
terraform_version: "1.9.8"
terraform_wrapper: false
- name: Terraform fmt
run: terraform fmt -check -recursive terraform
- name: Validate live/dev
run: |
terraform -chdir=terraform/live/dev init -backend=false
terraform -chdir=terraform/live/dev validate
- name: Validate live/staging
run: |
terraform -chdir=terraform/live/staging init -backend=false
terraform -chdir=terraform/live/staging validate
- name: Import plan guard tests
run: python3 scripts/test-terraform-import-plan-check.py
- name: Release promotion script tests
run: |
python3 scripts/test_next_release_tag.py
python3 scripts/test_require_commit_checks.py
python3 scripts/test_check_app_terraform_isolation.py