shoc-frontend-new/.github/workflows/terraform-isolation.yaml
Adam Moussa 08da408a13
ci(governance): wire Terraform and CDK gates and isolate Terraform PRs
Governance now runs the import-plan checker tests, Terraform fmt and
validate for terraform/live/dev, the isolation gate tests, and the CDK
build, tests, and synth in both modes. A new terraform-isolation
workflow fails PRs that change terraform/** together with application
code; the terraform-isolation-override label is the reviewed exception.
Renovate gains the terraform manager.
2026-09-10 19:15:13 -04:00

35 lines
1.3 KiB
YAML

name: Terraform isolation
# Fails a pull request that changes `terraform/**` together with deployable
# application code (see scripts/check-terraform-isolation.mjs). A merge that
# does both queues an HCP VCS run and a content release at the same time, and
# the two race for the workspace lock.
#
# Runs on label events too, so adding or removing the
# `terraform-isolation-override` label re-evaluates the gate without a push.
on:
pull_request:
branches: [main, dev, staging]
types: [opened, synchronize, reopened, labeled, unlabeled]
permissions:
contents: read
jobs:
terraform-isolation:
name: Terraform and application changes are isolated
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
- name: Check changed files
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
TERRAFORM_ISOLATION_OVERRIDE: ${{ contains(github.event.pull_request.labels.*.name, 'terraform-isolation-override') }}
run: node scripts/check-terraform-isolation.mjs --base "${BASE_SHA}" --head "${HEAD_SHA}"