mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 10:23:11 +00:00
Governance now runs the import-plan checker tests, Terraform fmt and validate for terraform/live/dev, the isolation gate tests, and the CDK build, tests, and synth in both modes. A new terraform-isolation workflow fails PRs that change terraform/** together with application code; the terraform-isolation-override label is the reviewed exception. Renovate gains the terraform manager.
35 lines
1.3 KiB
JavaScript
35 lines
1.3 KiB
JavaScript
import { spawnSync } from "node:child_process";
|
|
import path from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..");
|
|
const TERRAFORM = process.env.TERRAFORM_BIN || "terraform";
|
|
// Only dev has a live root. Staging adoption (SH-287) adds its own root here.
|
|
const ENVIRONMENTS = ["dev"];
|
|
const ROOTS = ENVIRONMENTS.map((environment) => path.join(ROOT, "terraform", "live", environment));
|
|
|
|
function run(args, cwd = ROOT) {
|
|
const result = spawnSync(TERRAFORM, args, {
|
|
cwd,
|
|
encoding: "utf8",
|
|
stdio: "inherit",
|
|
});
|
|
if (result.error) {
|
|
throw new Error(`could not start Terraform: ${result.error.message}`, {
|
|
cause: result.error,
|
|
});
|
|
}
|
|
if (result.status !== 0) {
|
|
throw new Error(`terraform ${args.join(" ")} failed with exit code ${result.status}`);
|
|
}
|
|
}
|
|
|
|
run(["fmt", "-check", "-recursive", path.join(ROOT, "terraform")]);
|
|
for (const root of ROOTS) {
|
|
// -backend=false never touches HCP state; -lockfile=readonly refuses to
|
|
// silently rewrite the committed provider lock.
|
|
run(["init", "-backend=false", "-input=false", "-lockfile=readonly", "-no-color"], root);
|
|
run(["validate", "-no-color"], root);
|
|
}
|
|
|
|
console.log(`Terraform formatting and validation passed for ${ENVIRONMENTS.join(", ")}.`);
|