name: Terraform CI # Static checks only. Plans run in HCP Terraform as speculative VCS runs on # the PR (shoc-frontend-new-dev and shoc-frontend-new-staging). Applies are # HCP auto-apply on merge to main (dev) and on a vX.Y.Z-staging tag (staging). on: pull_request: branches: [main, dev] paths: - "terraform/**" - "scripts/**" - ".github/workflows/ci-terraform.yaml" - ".github/workflows/deploy-web.yaml" push: branches: [main] paths: - "terraform/**" - "scripts/**" - ".github/workflows/ci-terraform.yaml" permissions: contents: read jobs: terraform: runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1 with: terraform_version: "1.16.0" terraform_wrapper: false - name: Terraform fmt run: terraform fmt -check -recursive terraform - name: Validate live/dev run: | terraform -chdir=terraform/live/dev init -backend=false -input=false -lockfile=readonly -no-color terraform -chdir=terraform/live/dev validate -no-color - name: Validate live/staging run: | terraform -chdir=terraform/live/staging init -backend=false -input=false -lockfile=readonly -no-color terraform -chdir=terraform/live/staging validate -no-color - name: Import plan guard tests run: python3 scripts/test-terraform-import-plan-check.py - name: App/Terraform isolation tests run: python3 scripts/test_check_app_terraform_isolation.py