name: Terraform isolation # Own workflow so labeled/unlabeled re-evaluate this gate without starting a # new Frontend checks run. Skipping jobs inside `ci.yaml` on those events # would report required checks as success and could merge a failing SHA. on: pull_request: branches: [main, dev, staging] types: - opened - synchronize - reopened - labeled - unlabeled permissions: contents: read jobs: terraform-isolation: # Fails a pull request that changes Terraform infrastructure together with # deployable application code (scripts/check-terraform-isolation.mjs). A # merge that does both queues an HCP VCS run and a content release at the # same time, and the two race for the workspace lock. The # `terraform-isolation-override` label is the reviewed exception. This # job is unconditional so adding or removing that label always reads the # current label set; a previous green check does not survive removal. name: Terraform and application changes are isolated runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: "24" - name: Check changed files env: BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} TERRAFORM_ISOLATION_OVERRIDE: ${{ contains(github.event.pull_request.labels.*.name, 'terraform-isolation-override') }} run: node scripts/check-terraform-isolation.mjs --base "${BASE_SHA}" --head "${HEAD_SHA}"