mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 16:13:12 +00:00
* ci(terraform-isolation): re-evaluate the gate on label changes * test(terraform-isolation): lock the ci.yaml label-event contract * fix(terraform-isolation): do not treat terraform markdown as a mixed change * fix(ci): do not skip Frontend checks on isolation label events * ci(terraform-isolation): run label retriggers in a dedicated workflow * fix: apply eslint formatting * fix: apply additional missed eslint formatting
43 lines
1.7 KiB
YAML
43 lines
1.7 KiB
YAML
name: Terraform isolation
|
|
|
|
# Own workflow so labeled/unlabeled re-evaluate this gate without starting a
|
|
# new Frontend checks run. Skipping jobs inside `ci.yaml` on those events
|
|
# would report required checks as success and could merge a failing SHA.
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main, dev, staging]
|
|
types:
|
|
- opened
|
|
- synchronize
|
|
- reopened
|
|
- labeled
|
|
- unlabeled
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
terraform-isolation:
|
|
# Fails a pull request that changes Terraform infrastructure together with
|
|
# deployable application code (scripts/check-terraform-isolation.mjs). A
|
|
# merge that does both queues an HCP VCS run and a content release at the
|
|
# same time, and the two race for the workspace lock. The
|
|
# `terraform-isolation-override` label is the reviewed exception. This
|
|
# job is unconditional so adding or removing that label always reads the
|
|
# current label set; a previous green check does not survive removal.
|
|
name: Terraform and application changes are isolated
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
fetch-depth: 0
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version: "24"
|
|
- name: Check changed files
|
|
env:
|
|
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
TERRAFORM_ISOLATION_OVERRIDE: ${{ contains(github.event.pull_request.labels.*.name, 'terraform-isolation-override') }}
|
|
run: node scripts/check-terraform-isolation.mjs --base "${BASE_SHA}" --head "${HEAD_SHA}"
|