mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 22:53:15 +00:00
* feat(infra): migrate syslog-server to HCP Terraform Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the collector is owned by Terraform before UniFi cutover. * fix(infra): keep no-logs alarm quiet until UniFi cutover The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply. * fix(infra): allow scoped apply to modify SG rules in place Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
64 lines
1.5 KiB
YAML
64 lines
1.5 KiB
YAML
name: CI
|
|
on:
|
|
pull_request:
|
|
branches: [main]
|
|
merge_group:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
terraform:
|
|
name: Terraform
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
defaults:
|
|
run:
|
|
working-directory: terraform
|
|
steps:
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: hashicorp/setup-terraform@dfe3c3f87815947d99a8997f908cb6525fc44e9e # v4.0.1
|
|
with:
|
|
terraform_version: "1.16.0"
|
|
terraform_wrapper: false
|
|
|
|
- name: Terraform fmt
|
|
run: terraform fmt -check -recursive
|
|
|
|
- name: Terraform init
|
|
run: terraform init -backend=false
|
|
|
|
- name: Terraform validate
|
|
run: terraform validate
|
|
|
|
ci:
|
|
name: ci / ci
|
|
needs: [terraform]
|
|
if: ${{ always() && !cancelled() }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
steps:
|
|
- name: Check jobs
|
|
env:
|
|
TERRAFORM_RESULT: ${{ needs.terraform.result }}
|
|
run: |
|
|
set -euo pipefail
|
|
fail=0
|
|
check() {
|
|
local name="$1"
|
|
local result="$2"
|
|
case "${result}" in
|
|
success)
|
|
echo "${name}: ${result}"
|
|
;;
|
|
*)
|
|
echo "${name}: ${result}" >&2
|
|
fail=1
|
|
;;
|
|
esac
|
|
}
|
|
check terraform "${TERRAFORM_RESULT}"
|
|
exit "${fail}"
|