-
Notifications
You must be signed in to change notification settings - Fork 0
60 lines (53 loc) · 1.44 KB
/
Copy pathtf-plan.yml
File metadata and controls
60 lines (53 loc) · 1.44 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
name: Terraform Plan (PR)
on:
pull_request:
permissions:
contents: read
id-token: write
pull-requests: write
jobs:
changes:
runs-on: ubuntu-latest
outputs:
terraform: ${{ steps.changed-files.outputs.any_changed }}
steps:
- uses: actions/checkout@v7
- name: Detect Terraform changes
id: changed-files
uses: tj-actions/changed-files@v47
with:
files: |
src/tf/**
.github/workflows/tf-plan.yml
validate:
needs: changes
if: ${{ needs.changes.outputs.terraform == 'true' }}
uses: glitchedmob/infra-gha/.github/workflows/tf-validate.yml@v0.7.4
with:
init-backend: false
plan:
needs:
- changes
- validate
if: ${{ needs.changes.outputs.terraform == 'true' }}
uses: glitchedmob/infra-gha/.github/workflows/tf-plan-apply.yml@v0.7.4
with:
plan-only: true
secrets:
envrc_content: |
export TF_VAR_github_app_pem="${{ secrets.TF_VAR_GITHUB_APP_PEM }}"
aws_role_arn: ${{ secrets.AWS_ROLE_ARN }}
output_encryption_key: ${{ secrets.OUTPUT_ENCRYPTION_KEY }}
result:
name: Terraform checks
if: ${{ always() }}
needs:
- changes
- validate
- plan
runs-on: ubuntu-latest
steps:
- uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe # release/v1
with:
allowed-skips: validate, plan
jobs: ${{ toJSON(needs) }}