mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 09:33:13 +00:00
* feat(terraform): add safe backend environment adoption Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer. * ci(deploy): pause dev and staging deployments Prevent application releases from racing Terraform adoption while retaining production deployment and validation. * ci(deploy): require manual environment dispatch * fix: update `required_version` from `>=1.7.0` to `>=1.9.0` The deploy-boundary check interpolates `var.aws_account_id` and `var.environment`. Terraform only allows other variables inside `validation` from 1.9.0+. CI already runs against `1.9.8` so `versions.tf` setting version as `>=1.7.0` is a breaking finding * chore(deps): add `terraform` to renovate dependency coverage * ci(deploy): drop unprovisioned prod dispatch path
75 lines
2 KiB
YAML
75 lines
2 KiB
YAML
name: Backend CI
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main, dev, staging]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-and-test:
|
|
name: Build and test
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
concurrency:
|
|
group: backend-ci-${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v7
|
|
|
|
- name: Set up .NET
|
|
uses: actions/setup-dotnet@v6
|
|
with:
|
|
dotnet-version: "8.0.x"
|
|
|
|
- name: Set up Terraform
|
|
uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
|
|
with:
|
|
terraform_version: "1.9.8"
|
|
|
|
- name: Restore
|
|
run: dotnet restore SeaHavenIndustries.sln
|
|
|
|
- name: Build
|
|
run: dotnet build SeaHavenIndustries.sln --no-restore --configuration Release
|
|
|
|
- name: Test
|
|
run: dotnet test SeaHavenIndustries.sln --no-build --configuration Release
|
|
|
|
- name: Terraform fmt and validate
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
directories=()
|
|
case "${{ github.base_ref }}" in
|
|
dev)
|
|
directories+=(terraform/live/tf-poc terraform/live/dev)
|
|
;;
|
|
staging)
|
|
directories+=(terraform/live/staging)
|
|
;;
|
|
esac
|
|
|
|
for dir in "${directories[@]}"; do
|
|
terraform -chdir="$dir" fmt -check -recursive
|
|
terraform -chdir="$dir" init -backend=false
|
|
terraform -chdir="$dir" validate
|
|
done
|
|
|
|
- name: Terraform import plan guard tests
|
|
run: python scripts/test-terraform-import-plan-check.py
|
|
|
|
- name: Set up Node.js
|
|
if: github.base_ref == 'dev'
|
|
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
|
|
with:
|
|
node-version: "24"
|
|
|
|
- name: Validate CDK deployment infrastructure
|
|
if: github.base_ref == 'dev'
|
|
working-directory: infra/cdk
|
|
run: |
|
|
npm ci
|
|
npm run synth
|