shoc-backend/scripts/test-terraform-import-plan-check.py
Adam Moussa 25c2e84e8f feat(terraform): adopt live deployment roles safely
Add import-only dev and staging state with least-privilege HCP authentication and plan safety guards.
2026-08-28 19:12:34 -04:00

69 lines
2.1 KiB
Python

#!/usr/bin/env python3
"""Small deterministic tests for check-terraform-import-plan.py."""
from __future__ import annotations
import json
import subprocess
import sys
import tempfile
from pathlib import Path
SCRIPT = Path(__file__).with_name("check-terraform-import-plan.py")
def run_case(actions: list[str], *, allow_update: bool = False) -> subprocess.CompletedProcess[str]:
plan = {
"resource_changes": [
{
"address": "module.deploy_role.aws_iam_role.github_deploy",
"mode": "managed",
"type": "aws_iam_role",
"change": {"actions": actions},
}
]
}
with tempfile.TemporaryDirectory() as directory:
plan_path = Path(directory) / "plan.json"
plan_path.write_text(json.dumps(plan), encoding="utf-8")
command = [sys.executable, str(SCRIPT), str(plan_path)]
if allow_update:
command.append("--allow-update")
return subprocess.run(command, check=False, capture_output=True, text=True)
def main() -> int:
cases = [
("no-op import", run_case(["no-op"]), 0),
("initial update", run_case(["update"]), 1),
("controlled update", run_case(["update"], allow_update=True), 0),
("create", run_case(["create"]), 1),
("replacement", run_case(["delete", "create"]), 1),
("destroy", run_case(["delete"]), 1),
]
failures = [
(name, result, expected)
for name, result, expected in cases
if result.returncode != expected
]
if failures:
print(
"FAIL: plan-check cases failed: "
+ ", ".join(name for name, _, _ in failures),
file=sys.stderr,
)
for name, result, expected in failures:
print(
f"{name}: expected {expected}, got {result.returncode}\n"
f"{result.stdout}{result.stderr}",
file=sys.stderr,
)
return 1
print("PASS: Terraform import plan safety checks")
return 0
if __name__ == "__main__":
raise SystemExit(main())