shoc-backend/scripts/validate-elastic-beanstalk-bundle.sh
Adam Moussa 77c3016c9d
Some checks are pending
Validate and deploy / Validate deployable source bundle (push) Waiting to run
Validate and deploy / Deploy shoc-backend-dev through Terraform (push) Blocked by required conditions
Validate and deploy / Deploy shoc-backend-staging to Elastic Beanstalk (push) Blocked by required conditions
feat(deploy): move dev application CD through Terraform (#102)
* feat(deploy): move dev application CD through Terraform

GitHub creates the immutable Elastic Beanstalk version; HCP Terraform is the only UpdateEnvironment caller via a guarded version_label run.

* fix: add permissions block for dependency-review workflow

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>

* fix(terraform): stop pinning the generated dev instance SG

---------

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-09-03 14:12:06 +00:00

34 lines
1.1 KiB
Bash
Executable file

#!/usr/bin/env bash
#
# Validate the exact Elastic Beanstalk bundle that a release will upload.
set -euo pipefail
BUNDLE="${1:-.artifacts/elastic-beanstalk/site.zip}"
die() {
printf 'ERR %s\n' "$1" >&2
exit 1
}
[[ -f "$BUNDLE" ]] || die "bundle does not exist: $BUNDLE"
[[ "$BUNDLE" == *.zip ]] || die "bundle must be a .zip file"
contents_file="$(mktemp)"
webhook_file="$(mktemp)"
trap 'rm -f "$contents_file" "$webhook_file"' EXIT
unzip -tq "$BUNDLE"
unzip -Z1 "$BUNDLE" > "$contents_file"
grep -Fxq "efbundle" "$contents_file"
grep -Fxq ".ebextensions/01_migrations.config" "$contents_file"
grep -Fxq ".ebextensions/02_webhook_config.config" "$contents_file"
unzip -p "$BUNDLE" .ebextensions/02_webhook_config.config > "$webhook_file"
grep -Fxq ' WorkOrderWebhook__Enabled: "true"' "$webhook_file"
grep -Fxq ' WorkOrderWebhook__Region: us-east-1' "$webhook_file"
grep -Fxq \
' WorkOrderWebhook__SecretId: arn:aws:secretsmanager:us-east-1:011934824531:secret:workorder-ingest/shoc-webhook-hmac-puYTcB' \
"$webhook_file"
printf 'PASS: Elastic Beanstalk bundle contract (%s bytes)\n' \
"$(wc -c < "$BUNDLE" | tr -d ' ')"