mirror of
https://github.com/Sea-Haven-Industries/shoc-frontend-new.git
synced 2026-09-30 13:53:12 +00:00
Some checks failed
Deploy dev content / Deploy shoc-frontend-new-dev through Terraform (push) Has been cancelled
* ci(cd): convert SPA hosting to handbook HCP and GitHub content CD Give HCP the bucket and CloudFront with an empty origin path. GitHub owns bucket-root sync and invalidation so merge-to-main and a human staging tag can deploy without creating HCP runs. G13 fails PRs that mix terraform/ with deployable application files. * ci: run Frontend checks and Terraform CI on PRs to main and dev Match backend 148 so a PR targeting origin/dev still gets the required checks. Push remains main only. * refactor(terraform): keep live/dev and live/staging as HCP roots Leave the adopted working directories in place so this CD PR does not retarget two live HCP workspaces. Flattening stays a later change. * style: prettier terraform-validate.mjs * fix(terraform): pin githubdeploy assume-role policy in import checker Reject controlled role updates whose trust document is not the rendered GitHub OIDC policy, matching the bucket-policy pin.
36 lines
1.1 KiB
JavaScript
36 lines
1.1 KiB
JavaScript
#!/usr/bin/env node
|
|
import { spawnSync } from "node:child_process";
|
|
import path from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..");
|
|
const TERRAFORM = process.env.TERRAFORM_BIN || "terraform";
|
|
const LIVE_ROOTS = ["terraform/live/dev", "terraform/live/staging"];
|
|
|
|
function run(args, cwd = ROOT, env = process.env) {
|
|
const result = spawnSync(TERRAFORM, args, {
|
|
cwd,
|
|
encoding: "utf8",
|
|
stdio: "inherit",
|
|
env,
|
|
});
|
|
if (result.error) {
|
|
throw new Error(`could not start Terraform: ${result.error.message}`, {
|
|
cause: result.error,
|
|
});
|
|
}
|
|
if (result.status !== 0) {
|
|
throw new Error(`terraform ${args.join(" ")} failed with exit code ${result.status}`);
|
|
}
|
|
}
|
|
|
|
run(["fmt", "-check", "-recursive", "terraform"]);
|
|
for (const liveRoot of LIVE_ROOTS) {
|
|
const abs = path.join(ROOT, liveRoot);
|
|
run(["init", "-backend=false", "-input=false", "-lockfile=readonly", "-no-color"], abs);
|
|
run(["validate", "-no-color"], abs);
|
|
}
|
|
|
|
console.log(
|
|
"Terraform formatting and validation passed for terraform/live/dev and terraform/live/staging.",
|
|
);
|