shoc-backend/scripts/governance-check.sh
Adam Moussa 24f08d3cb1
feat(terraform): adopt live deployment roles safely (#94)
* feat(terraform): add safe backend environment adoption

Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.

* ci(deploy): pause dev and staging deployments

Prevent application releases from racing Terraform adoption while retaining production deployment and validation.

* ci(deploy): require manual environment dispatch

* fix: update `required_version` from `>=1.7.0` to `>=1.9.0`

The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+.

CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding

* chore(deps): add `terraform` to renovate dependency coverage

* ci(deploy): drop unprovisioned prod dispatch path
2026-08-31 11:51:18 -04:00

86 lines
2.8 KiB
Bash
Executable file

#!/usr/bin/env bash
#
# governance-check.sh — local/CI parity governance gate for the Seahaven backend.
#
# Runs G1 restore, G2 ArchitectureTests, G3 changed-file formatting, G4 Release
# build, and G5 full tests exactly as the `architecture-quality` workflow does.
# A green run here means the same thing locally and in that CI workflow.
#
# Usage:
# bash scripts/governance-check.sh
# BASE_REF=origin/dev bash scripts/governance-check.sh
# BASE_REF=<base-sha> HEAD_REF=<head-sha> bash scripts/governance-check.sh
set -euo pipefail
SOLUTION="SeaHavenIndustries.sln"
ARCH_TEST_PROJECT="Api.SeaHavenIndustries.Tests/Api.SeaHavenIndustries.Tests.csproj"
log() { printf '\n\033[1m== %s ==\033[0m\n' "$1"; }
ok() { printf '\033[32mPASS\033[0m %s\n' "$1"; }
bad() { printf '\033[31mFAIL\033[0m %s\n' "$1"; }
if [[ -n "${DOTNET_BIN:-}" ]]; then
DOTNET="$DOTNET_BIN"
elif command -v dotnet >/dev/null 2>&1; then
DOTNET="$(command -v dotnet)"
elif [[ -x "$HOME/.dotnet/dotnet" ]]; then
DOTNET="$HOME/.dotnet/dotnet"
else
bad "dotnet is unavailable; set DOTNET_BIN or install the repository SDK."
exit 1
fi
# Comparison point for changed-file formatting. Default to the dev integration
# branch locally; CI overrides BASE_REF/HEAD_REF with the PR base/head SHAs.
BASE_REF="${BASE_REF:-origin/dev}"
HEAD_REF="${HEAD_REF:-HEAD}"
# Resolve the base ref before using it for a diff.
if ! git rev-parse --verify --quiet "${BASE_REF}^{commit}" >/dev/null; then
bad "G3: BASE_REF '${BASE_REF}' does not resolve to a commit (run: git fetch origin)."
exit 1
fi
log "G1: restore"
"$DOTNET" restore "$SOLUTION"
ok "G1: restore"
log "G2: architecture boundary tests (dependency direction)"
"$DOTNET" test "$ARCH_TEST_PROJECT" \
--no-restore \
--filter "FullyQualifiedName~ArchitectureTests" \
--nologo
ok "G2: ArchitectureTests"
log "G3: changed-file formatting (${BASE_REF}..${HEAD_REF})"
changed_cs=()
while IFS= read -r f; do
changed_cs+=("$f")
done < <(
git diff --name-only --diff-filter=ACMR "${BASE_REF}" "${HEAD_REF}" -- '*.cs'
)
if (( ${#changed_cs[@]} == 0 )); then
printf '\033[33mSKIP\033[0m G3: no changed C# files between %s..%s\n' "${BASE_REF}" "${HEAD_REF}"
else
printf ' checking %d changed C# file(s)\n' "${#changed_cs[@]}"
"$DOTNET" format "$SOLUTION" \
--no-restore \
--verify-no-changes \
--include "${changed_cs[@]}"
ok "G3: changed-file formatting"
fi
log "G4: Release build"
"$DOTNET" build "$SOLUTION" -c Release --no-restore --nologo
ok "G4: Release build"
log "G5: full test suite"
"$DOTNET" test "$SOLUTION" -c Release --no-build --nologo
ok "G5: full test suite"
log "G10: Terraform import plan safety"
python scripts/test-terraform-import-plan-check.py
ok "G10: Terraform import plan safety"
log "governance-check: all required repository gates passed"