mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-10-07 16:19:01 +00:00
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns bucket-root sync and invalidation so merge-to-main and a human staging tag can deploy without creating HCP runs. G13 fails PRs that mix terraform/ with deployable application files.
40 lines
1.3 KiB
JavaScript
40 lines
1.3 KiB
JavaScript
#!/usr/bin/env node
|
|
import { spawnSync } from "node:child_process";
|
|
import path from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..");
|
|
const TERRAFORM = process.env.TERRAFORM_BIN || "terraform";
|
|
const TERRAFORM_ROOT = path.join(ROOT, "terraform");
|
|
|
|
function run(args, cwd = TERRAFORM_ROOT, env = process.env) {
|
|
const result = spawnSync(TERRAFORM, args, {
|
|
cwd,
|
|
encoding: "utf8",
|
|
stdio: "inherit",
|
|
env,
|
|
});
|
|
if (result.error) {
|
|
throw new Error(`could not start Terraform: ${result.error.message}`, {
|
|
cause: result.error,
|
|
});
|
|
}
|
|
if (result.status !== 0) {
|
|
throw new Error(`terraform ${args.join(" ")} failed with exit code ${result.status}`);
|
|
}
|
|
}
|
|
|
|
run(["fmt", "-check", "-recursive", TERRAFORM_ROOT], ROOT);
|
|
// -backend=false never touches HCP state; -lockfile=readonly refuses to
|
|
// silently rewrite the committed provider lock.
|
|
run(["init", "-backend=false", "-input=false", "-lockfile=readonly", "-no-color"]);
|
|
run(["validate", "-no-color"], TERRAFORM_ROOT, {
|
|
...process.env,
|
|
TF_VAR_environment: "dev",
|
|
});
|
|
run(["validate", "-no-color"], TERRAFORM_ROOT, {
|
|
...process.env,
|
|
TF_VAR_environment: "staging",
|
|
});
|
|
|
|
console.log("Terraform formatting and validation passed for terraform/.");
|