* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
* ci: run Frontend checks and Terraform CI on PRs to main and dev
Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.
* refactor(terraform): keep live/dev and live/staging as HCP roots
Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.
* style: prettier terraform-validate.mjs
* fix(terraform): pin githubdeploy assume-role policy in import checker
Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
Capturing the curl body in "$(...)" strips the trailing newline, so the
served sha256 never matched dist/index.html and every release and rollback
verify polled to the budget and failed. Hash the response stream directly
and give the test fixture a trailing newline so the suite covers it.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)