shoc-backend/.github/workflows/ci.yml
Adam Moussa f8bf102f35 feat(terraform): add safe backend environment adoption
Introduce import-guarded environment roots and retire temporary bootstrap and POC provisioning after ownership transfer.
2026-08-30 16:34:38 -04:00

75 lines
2 KiB
YAML

name: Backend CI
on:
pull_request:
branches: [main, dev, staging]
permissions:
contents: read
jobs:
build-and-test:
name: Build and test
runs-on: ubuntu-latest
timeout-minutes: 20
concurrency:
group: backend-ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Set up .NET
uses: actions/setup-dotnet@v6
with:
dotnet-version: "8.0.x"
- name: Set up Terraform
uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
with:
terraform_version: "1.9.8"
- name: Restore
run: dotnet restore SeaHavenIndustries.sln
- name: Build
run: dotnet build SeaHavenIndustries.sln --no-restore --configuration Release
- name: Test
run: dotnet test SeaHavenIndustries.sln --no-build --configuration Release
- name: Terraform fmt and validate
run: |
set -euo pipefail
directories=()
case "${{ github.base_ref }}" in
dev)
directories+=(terraform/live/tf-poc terraform/live/dev)
;;
staging)
directories+=(terraform/live/staging)
;;
esac
for dir in "${directories[@]}"; do
terraform -chdir="$dir" fmt -check -recursive
terraform -chdir="$dir" init -backend=false
terraform -chdir="$dir" validate
done
- name: Terraform import plan guard tests
run: python scripts/test-terraform-import-plan-check.py
- name: Set up Node.js
if: github.base_ref == 'dev'
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: "24"
- name: Validate CDK deployment infrastructure
if: github.base_ref == 'dev'
working-directory: infra/cdk
run: |
npm ci
npm run synth