Commit graph

10 commits

Author SHA1 Message Date
7ed0743b90
fix(terraform): pin SSM deploy parameter tier and data_type
HCP tried to replace the live parameters on refresh because those
attributes were computed. The apply role cannot DeleteParameter.
2026-09-18 15:09:56 -04:00
ceecab5438
fix(cd): ignore githubdeploy description and retire leftover pointer CD
SCP denies UpdateRoleDescription on githubdeploy-*, so HCP apply cannot
rewrite the role description. Pointer workflows must not land on main.
2026-09-18 15:04:51 -04:00
Adam Moussa
c96a259365
refactor(cd): ship SPA content from GitHub on main (#220)
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD

Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.

* ci: run Frontend checks and Terraform CI on PRs to main and dev

Match backend 148 so a PR targeting origin/dev still gets the required
checks. Push remains main only.

* refactor(terraform): keep live/dev and live/staging as HCP roots

Leave the adopted working directories in place so this CD PR does not
retarget two live HCP workspaces. Flattening stays a later change.

* style: prettier terraform-validate.mjs

* fix(terraform): pin githubdeploy assume-role policy in import checker

Reject controlled role updates whose trust document is not the rendered
GitHub OIDC policy, matching the bucket-policy pin.
2026-09-18 14:30:20 -04:00
Adam Moussa
69c24c1c2c
feat(terraform): ship dev content CD through Terraform (SH-300) (#180)
* feat(terraform): ship dev content CD through Terraform (SH-300)

GitHub uploads immutable release prefixes; Terraform owns live publish.
Push-to-dev stays off until TERRAFORM_CONTENT_CD_ENABLED is set.

* fix(terraform): align release-plan guard flags and CloudFront verify IAM (SH-300)
2026-09-11 13:40:14 -04:00
f532aa6059
feat(terraform): complete dev environment adoption (SH-300) 2026-09-11 11:22:28 -04:00
Adam Moussa
8b5281d357
ci(terraform-isolation): re-evaluate the gate on label changes (#177)
Some checks are pending
Frontend checks / Build and test (push) Waiting to run
Frontend checks / governance (push) Waiting to run
Frontend checks / Visual regression (push) Waiting to run
* ci(terraform-isolation): re-evaluate the gate on label changes

* test(terraform-isolation): lock the ci.yaml label-event contract

* fix(terraform-isolation): do not treat terraform markdown as a mixed change

* fix(ci): do not skip Frontend checks on isolation label events

* ci(terraform-isolation): run label retriggers in a dedicated workflow

* fix: apply eslint formatting

* fix: apply additional missed eslint formatting
2026-09-10 20:45:49 -04:00
8ec91f0dac
ci: run the Terraform isolation gate as a job in the CI workflow 2026-09-10 19:37:27 -04:00
7ab6fa30e7
fix(terraform): lock provider hashes for linux and darwin platforms 2026-09-10 19:34:10 -04:00
0bc7e22884
docs(terraform): mark the isolation override as temporary 2026-09-10 19:22:43 -04:00
78398482cf
feat(terraform): add dev root and import guard for HCP adoption
Port the reviewed dev root and environment-owned/inventory modules from
111eb556 with the 13 pinned dev identifiers. adoption_complete is pinned
to false in code; the root has no variables so a workspace variable
cannot change what applies. The tf-poc root, staging root, and tf-poc
map entries are dropped; staging constants stay only for the checker's
cross-environment negative tests.
2026-09-10 19:15:09 -04:00