mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-10-02 03:53:13 +00:00
Governance now runs the import-plan checker tests, Terraform fmt and validate for terraform/live/dev, the isolation gate tests, and the CDK build, tests, and synth in both modes. A new terraform-isolation workflow fails PRs that change terraform/** together with application code; the terraform-isolation-override label is the reviewed exception. Renovate gains the terraform manager.
35 lines
1.3 KiB
YAML
35 lines
1.3 KiB
YAML
name: Terraform isolation
|
|
|
|
# Fails a pull request that changes `terraform/**` together with deployable
|
|
# application code (see scripts/check-terraform-isolation.mjs). A merge that
|
|
# does both queues an HCP VCS run and a content release at the same time, and
|
|
# the two race for the workspace lock.
|
|
#
|
|
# Runs on label events too, so adding or removing the
|
|
# `terraform-isolation-override` label re-evaluates the gate without a push.
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main, dev, staging]
|
|
types: [opened, synchronize, reopened, labeled, unlabeled]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
terraform-isolation:
|
|
name: Terraform and application changes are isolated
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
fetch-depth: 0
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
- name: Check changed files
|
|
env:
|
|
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
TERRAFORM_ISOLATION_OVERRIDE: ${{ contains(github.event.pull_request.labels.*.name, 'terraform-isolation-override') }}
|
|
run: node scripts/check-terraform-isolation.mjs --base "${BASE_SHA}" --head "${HEAD_SHA}"
|