shoc-frontend-new/scripts/terraform-validate.mjs
Adam Moussa 2a106d4e9e
ci(cd): convert SPA hosting to handbook HCP and GitHub content CD
Give HCP the bucket and CloudFront with an empty origin path. GitHub owns
bucket-root sync and invalidation so merge-to-main and a human staging tag
can deploy without creating HCP runs. G13 fails PRs that mix terraform/
with deployable application files.
2026-09-17 15:55:25 -04:00

40 lines
1.3 KiB
JavaScript

#!/usr/bin/env node
import { spawnSync } from "node:child_process";
import path from "node:path";
import { fileURLToPath } from "node:url";
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..");
const TERRAFORM = process.env.TERRAFORM_BIN || "terraform";
const TERRAFORM_ROOT = path.join(ROOT, "terraform");
function run(args, cwd = TERRAFORM_ROOT, env = process.env) {
const result = spawnSync(TERRAFORM, args, {
cwd,
encoding: "utf8",
stdio: "inherit",
env,
});
if (result.error) {
throw new Error(`could not start Terraform: ${result.error.message}`, {
cause: result.error,
});
}
if (result.status !== 0) {
throw new Error(`terraform ${args.join(" ")} failed with exit code ${result.status}`);
}
}
run(["fmt", "-check", "-recursive", TERRAFORM_ROOT], ROOT);
// -backend=false never touches HCP state; -lockfile=readonly refuses to
// silently rewrite the committed provider lock.
run(["init", "-backend=false", "-input=false", "-lockfile=readonly", "-no-color"]);
run(["validate", "-no-color"], TERRAFORM_ROOT, {
...process.env,
TF_VAR_environment: "dev",
});
run(["validate", "-no-color"], TERRAFORM_ROOT, {
...process.env,
TF_VAR_environment: "staging",
});
console.log("Terraform formatting and validation passed for terraform/.");