name: Terraform isolation # Fails a pull request that changes `terraform/**` together with deployable # application code (see scripts/check-terraform-isolation.mjs). A merge that # does both queues an HCP VCS run and a content release at the same time, and # the two race for the workspace lock. # # Runs on label events too, so adding or removing the # `terraform-isolation-override` label re-evaluates the gate without a push. on: pull_request: branches: [main, dev, staging] types: [opened, synchronize, reopened, labeled, unlabeled] permissions: contents: read jobs: terraform-isolation: name: Terraform and application changes are isolated runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" - name: Check changed files env: BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} TERRAFORM_ISOLATION_OVERRIDE: ${{ contains(github.event.pull_request.labels.*.name, 'terraform-isolation-override') }} run: node scripts/check-terraform-isolation.mjs --base "${BASE_SHA}" --head "${HEAD_SHA}"