-
Notifications
You must be signed in to change notification settings - Fork 0
164 lines (135 loc) · 4.79 KB
/
pr-terraform.yaml
File metadata and controls
164 lines (135 loc) · 4.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
on:
workflow_call:
inputs:
role_name:
required: true
type: string
role_session_name:
required: true
type: string
aws_region:
required: false
type: string
default: eu-central-1
working_directory:
required: true
type: string
permissions:
id-token: write
contents: read
pull-requests: write
statuses: write
jobs:
terraform:
name: Terraform
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: ${{ inputs.working_directory }}
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Configure AWS Credentials
id: aws
uses: aws-actions/configure-aws-credentials@v3
with:
role-to-assume: arn:aws:iam::${{ secrets.AWS_ACCOUNT_ID }}:role/github-actions-kubernetes-role
role-session-name: ga-kubernetes
aws-region: eu-central-1
- name: Download Staging Variables
uses: actions/download-artifact@v4
with:
name: staging-variables
path: ${{ inputs.working_directory }}
- name: Download Prod Variables
uses: actions/download-artifact@v4
with:
name: prod-variables
path: ${{ inputs.working_directory }}
- name: Setup Terraform
uses: hashicorp/setup-terraform@v2
with:
terraform_version: ~1.0
- name: Terraform Format
id: fmt
run: terraform fmt -check
- name: Terraform Init
id: init
run: terraform init
- name: Terraform Validate
id: validate
run: terraform validate -no-color
- name: Terraform Staging Plan
id: plan-staging
run: terraform plan -no-color -var-file=staging.tfvars.json
env:
TF_WORKSPACE: stg
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Terraform Prod Plan
id: plan-prod
run: terraform plan -no-color -var-file=prod.tfvars.json
env:
TF_WORKSPACE: prod
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- uses: actions/github-script@v6
if: github.event_name == 'pull_request'
env:
PLAN_STAGING: "terraform\n${{ steps.plan-staging.outputs.stdout }}"
PLAN_PROD: "terraform\n${{ steps.plan-prod.outputs.stdout }}"
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
// 1. Retrieve existing bot comments for the PR
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
})
const botComment = comments.find(comment => {
return comment.user.type === 'Bot' && comment.body.includes('Terraform Format and Style')
})
// 2. Prepare format of the comment
const output = `#### Terraform Format and Style 🖌\`${{ steps.fmt.outcome }}\`
#### Terraform Initialization ⚙️\`${{ steps.init.outcome }}\`
#### Terraform Validation 🤖\`${{ steps.validate.outcome }}\`
<details><summary>Validation Output</summary>
\`\`\`\n
${{ steps.validate.outputs.stdout }}
\`\`\`
</details>
#### Terraform Staging Plan 📖\`${{ steps.plan-staging.outcome }}\`
<details><summary>Show Staging Plan</summary>
\`\`\`\n
${process.env.PLAN_STAGING}
\`\`\`
</details>
#### Terraform Prod Plan 📖\`${{ steps.plan-prod.outcome }}\`
<details><summary>Show Prod Plan</summary>
\`\`\`\n
${process.env.PLAN_PROD}
\`\`\`
</details>
*Pusher: @${{ github.actor }}, Action: \`${{ github.event_name }}\`, Working Directory: \`${{ env.tf_actions_working_dir }}\`, Workflow: \`${{ github.workflow }}\`*`;
// 3. If we have a comment, update it, otherwise create a new one
if (botComment) {
github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: botComment.id,
body: output
})
} else {
github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
repo: context.repo.repo,
body: output
})
}
- name: Terraform Staging Plan Status
if: steps.plan-staging.outcome == 'failure'
run: exit 1
- name: Terraform Prod Plan Status
if: steps.plan-prod.outcome == 'failure'
run: exit 1