Capturing the curl body in "$(...)" strips the trailing newline, so the
served sha256 never matched dist/index.html and every release and rollback
verify polled to the budget and failed. Hash the response stream directly
and give the test fixture a trailing newline so the suite covers it.
* fix(terraform): ignore origin response_completion_timeout in the release plan guard (SH-300)
AWS returns 0 when the timeout is unset. The provider writes null on
origin_path updates, so the first real CD plan failed closed.
* fix(ci): drop duplicate verify from the content CD workflow (SH-300)
Frontend checks already runs verify on PRs and pushes. Removing the
validate job also requires dropping needs: validate so dispatch can run.
* fix(terraform): equate origin timeout 0 and null only (SH-300)
Numeric timeout changes still fail closed. Rename the filter so it is
not read as an after_unknown allowlist.
* feat(terraform): ship dev content CD through Terraform (SH-300)
GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.
* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
* ci(terraform-isolation): re-evaluate the gate on label changes
* test(terraform-isolation): lock the ci.yaml label-event contract
* fix(terraform-isolation): do not treat terraform markdown as a mixed change
* fix(ci): do not skip Frontend checks on isolation label events
* ci(terraform-isolation): run label retriggers in a dedicated workflow
* fix: apply eslint formatting
* fix: apply additional missed eslint formatting
Two-phase runbook, ownership boundary, workspace invariants, rollback
per phase, and operational rules in terraform/README.md; CDK adoption
mode and the retired cd-cdk path in infra/cdk/README.md; gate matrix and
deployment section updates.
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
Remove the push-to-dev trigger and the org cd-cdk.yaml caller so CI no
longer runs cdk deploy during the adoption. The workflow assumes the
pinned dev role and runs the simple scripts/deploy-web.sh against a
pinned bucket and distribution, which keeps content deploys working
after CloudFormation relinquishes the stack outputs. Staging is
untouched.
retainForTerraformAdoption=true adds the required ManageSiteInfrastructure
parameter, conditions the 13 transferred resources and the S3 auto-delete
custom resource on it, applies Retain policies, pins the live dev origin
ID, attaches the deploy boundary and HcpTerraformWorkspace tag, and
narrows the OIDC subject to StringEquals. Normal synthesis is unchanged;
template tests cover both modes.
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.
Three conflicts, all where dev refactored code this branch had instrumented:
- api.ts — dev extracted the session-expiry helper into
lib/auth/expire-session. Took dev's import, dropped the now-duplicate local
copy, kept the tracing import.
- work-order-board-documents-api.ts — dev replaced the ky upload with
uploadFormWithProgress, an XHR path that exists because ky's
onUploadProgress streams the body and browsers refuse that over HTTP/1.1.
Kept dev's helper and wrapped it in traceHttpOperation so the upload stays
instrumented; neither change is lost.
- work-orders-api.test.ts — kept both mock surfaces, since the merged
work-orders-api calls apiRequestRaw while other code uses the ky instance.
getMediaContent arrived from dev calling `api.get` directly, which this file
no longer imports; routed it through apiRequestRaw like its siblings, which
also brings it under tracing.