Skip to content

Add pre-commit framework (tofu fmt + formatters + betterleaks) + CI (#15, #123) - #16

Merged
nickvigilante merged 1 commit into
mainfrom
precommit-formatting
May 27, 2026
Merged

Add pre-commit framework (tofu fmt + formatters + betterleaks) + CI (#15, #123)#16
nickvigilante merged 1 commit into
mainfrom
precommit-formatting

Conversation

@nickvigilante

Copy link
Copy Markdown
Owner

Summary

Adds the pre-commit framework to the infrastructure repo, mirroring the homelab setup (nickvigilante/homelab#125). Closes #15.

Per file type: tofu fmt (Terraform), prettier (Markdown, aligns tables), yamlfmt + yamllint (YAML), standard hygiene hooks, and betterleaks replacing gitleaks (#123). .terraform.lock.hcl is left untouched.

CI: new lint.yml runs pre-commit run --all-files (installs tofu via setup-opentofu + prettier/yamlfmt/yamllint) — same hooks as local, so they can't drift. (This repo had no lint workflow before; only homelab-plan/apply.)

Notes

  • betterleaks reports the repo clean; the old .gitleaks.toml (defaults-only, no allowlist) and .githooks gitleaks hook are removed in favor of pre-commit install.
  • Reuses homelab's conservative .yamlfmt + permissive yamllint config.

Test plan

  • pre-commit run --all-files passes + idempotent; tofu fmt -recursive -check clean
  • CI pre-commit job green on this PR

@github-actions

Copy link
Copy Markdown

homelab tofu plan

Plan output
tailscale_dns_nameservers.global: Refreshing state... [id=34619e51-87ec-b5df-c078-fd2e3181d9c5]
tailscale_acl.main: Refreshing state... [id=acl]
tailscale_dns_preferences.main: Refreshing state... [id=ad9f64d5-f380-ae42-4811-7604bfdb5bcd]
data.github_user.self: Reading...
github_repository.managed["styleguide"]: Refreshing state... [id=styleguide]
github_repository.managed["tools"]: Refreshing state... [id=tools]
github_repository.managed["dotfiles"]: Refreshing state... [id=dotfiles]
github_repository.managed["infrastructure"]: Refreshing state... [id=infrastructure]
github_repository.managed["tuile"]: Refreshing state... [id=tuile]
github_repository.managed["homelab"]: Refreshing state... [id=homelab]
github_repository.managed["puzzles"]: Refreshing state... [id=puzzles]
github_repository.managed["vale-languagetool"]: Refreshing state... [id=vale-languagetool]
github_repository.managed["docs"]: Refreshing state... [id=docs]
github_repository.managed["passgen"]: Refreshing state... [id=passgen]
data.github_user.self: Read complete after 3s [id=13631471]
github_repository_environment.homelab_apply: Refreshing state... [id=infrastructure:homelab-apply]
github_actions_secret.tailscale_oauth_client_secret: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_SECRET]
github_repository_vulnerability_alerts.alerts["tools"]: Refreshing state... [id=177344790]
github_actions_secret.tailscale_oauth_client_id: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_ID]
github_repository_vulnerability_alerts.alerts["passgen"]: Refreshing state... [id=1007162400]
github_repository_vulnerability_alerts.alerts["homelab"]: Refreshing state... [id=1235102549]
github_repository_vulnerability_alerts.alerts["infrastructure"]: Refreshing state... [id=1234973546]
github_actions_secret.github_app_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_ID]
github_repository_vulnerability_alerts.alerts["docs"]: Refreshing state... [id=1213739034]
github_actions_secret.aws_secret_access_key: Refreshing state... [id=infrastructure:AWS_SECRET_ACCESS_KEY]
github_repository_vulnerability_alerts.alerts["tuile"]: Refreshing state... [id=1209980965]
github_repository_vulnerability_alerts.alerts["dotfiles"]: Refreshing state... [id=692319991]
github_actions_secret.github_app_installation_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_INSTALLATION_ID]
github_repository_vulnerability_alerts.alerts["styleguide"]: Refreshing state... [id=877056782]
github_repository_vulnerability_alerts.alerts["puzzles"]: Refreshing state... [id=1221351905]
github_repository_vulnerability_alerts.alerts["vale-languagetool"]: Refreshing state... [id=874539266]
github_branch_protection.main["tools"]: Refreshing state... [id=BPR_kwDOCpIRFs4CjUwo]
github_branch_protection.main["infrastructure"]: Refreshing state... [id=BPR_kwDOSZwzas4Ek1LQ]
github_branch_protection.main["homelab"]: Refreshing state... [id=BPR_kwDOSZ4rVc4Ek1bm]
github_branch_protection.main["passgen"]: Refreshing state... [id=BPR_kwDOPAgUIM4Ek1Lp]
github_branch_protection.main["styleguide"]: Refreshing state... [id=BPR_kwDONEbTDs4Ek1Lj]
github_branch_protection.main["dotfiles"]: Refreshing state... [id=BPR_kwDOKUP2984EclBF]
github_branch_protection.main["tuile"]: Refreshing state... [id=BPR_kwDOSB7YJc4Ek1LN]
github_branch_protection.main["puzzles"]: Refreshing state... [id=BPR_kwDOSMxZ4c4Ek1Lo]
github_branch_protection.main["vale-languagetool"]: Refreshing state... [id=BPR_kwDONCBpAs4Ek1LO]
github_branch_protection.main["docs"]: Refreshing state... [id=BPR_kwDOSFgwGs4Ek1Ll]
github_actions_secret.aws_access_key_id: Refreshing state... [id=infrastructure:AWS_ACCESS_KEY_ID]
github_actions_secret.github_app_private_key: Refreshing state... [id=infrastructure:TF_GITHUB_APP_PRIVATE_KEY]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.

@nickvigilante
nickvigilante merged commit ca2117c into main May 27, 2026
2 checks passed
@nickvigilante
nickvigilante deleted the precommit-formatting branch May 27, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Research pre-commit formatting/tidiness hooks (alongside gitleaks)

1 participant