mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 08:03:13 +00:00
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD Give HCP the bucket and CloudFront with an empty origin path. GitHub owns bucket-root sync and invalidation so merge-to-main and a human staging tag can deploy without creating HCP runs. G13 fails PRs that mix terraform/ with deployable application files. * ci: run Frontend checks and Terraform CI on PRs to main and dev Match backend 148 so a PR targeting origin/dev still gets the required checks. Push remains main only. * refactor(terraform): keep live/dev and live/staging as HCP roots Leave the adopted working directories in place so this CD PR does not retarget two live HCP workspaces. Flattening stays a later change. * style: prettier terraform-validate.mjs * fix(terraform): pin githubdeploy assume-role policy in import checker Reject controlled role updates whose trust document is not the rendered GitHub OIDC policy, matching the bucket-policy pin.
70 lines
2.2 KiB
Python
70 lines
2.2 KiB
Python
#!/usr/bin/env python3
|
|
"""Tests for check_app_terraform_isolation.isolation_violation."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import unittest
|
|
|
|
from check_app_terraform_isolation import isolation_violation
|
|
|
|
|
|
class IsolationTests(unittest.TestCase):
|
|
def test_terraform_only(self) -> None:
|
|
self.assertIsNone(
|
|
isolation_violation(
|
|
[
|
|
"terraform/live/dev/main.tf",
|
|
"terraform/live/README.md",
|
|
]
|
|
)
|
|
)
|
|
|
|
def test_app_only(self) -> None:
|
|
self.assertIsNone(
|
|
isolation_violation(
|
|
[
|
|
"src/app/routes.tsx",
|
|
"public/favicon.ico",
|
|
"index.html",
|
|
"scripts/deploy-web.sh",
|
|
]
|
|
)
|
|
)
|
|
|
|
def test_docs_workflows_and_gate_scripts_with_terraform(self) -> None:
|
|
self.assertIsNone(
|
|
isolation_violation(
|
|
[
|
|
"terraform/live/modules/environment-owned/main.tf",
|
|
".github/workflows/deploy-web.yaml",
|
|
"QUALITY_GATES.md",
|
|
"scripts/governance-check.mjs",
|
|
"scripts/check_app_terraform_isolation.py",
|
|
"package.json",
|
|
]
|
|
)
|
|
)
|
|
|
|
def test_mixed_src_and_terraform_fails(self) -> None:
|
|
violation = isolation_violation(
|
|
[
|
|
"terraform/live/dev/main.tf",
|
|
"src/app/routes.tsx",
|
|
]
|
|
)
|
|
self.assertIsNotNone(violation)
|
|
terraform_files, app_files = violation or ([], [])
|
|
self.assertEqual(terraform_files, ["terraform/live/dev/main.tf"])
|
|
self.assertEqual(app_files, ["src/app/routes.tsx"])
|
|
|
|
def test_mixed_vite_config_and_terraform_fails(self) -> None:
|
|
violation = isolation_violation(["terraform/live/dev/versions.tf", "vite.config.ts"])
|
|
self.assertIsNotNone(violation)
|
|
|
|
def test_mixed_env_and_terraform_fails(self) -> None:
|
|
violation = isolation_violation(["terraform/live/dev/main.tf", ".env.production"])
|
|
self.assertIsNotNone(violation)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|