Repository navigation
119 lines (100 loc) · 3.7 KB
/
Copy pathci.yml
File metadata and controls
119 lines (100 loc) · 3.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
name: CI
# Terraform hygiene + security checks. Set these jobs as required status
# checks in branch protection (Settings → Branches) so PRs can't merge red.
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
pre-commit:
name: pre-commit (fmt, validate, secrets)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Setup Terraform
uses: hashicorp/setup-terraform@v4
with:
terraform_version: "1.15.8"
terraform_wrapper: false
- name: Setup Python
uses: actions/setup-python@v6
with:
python-version: "3.12"
# gitleaks (secrets hook) needs full history to scan all commits on a PR.
- name: Fetch full history
run: git fetch --prune --unshallow || true
# Run pre-commit manually rather than via pre-commit/action@v3.0.1 — that
# action pins a Node-20-era actions/cache and emits a deprecation warning.
# This uses actions/cache@v6 (Node 24) directly for the hook-env cache.
- name: Cache pre-commit environments
uses: actions/cache@v6
with:
path: ~/.cache/pre-commit
key: pre-commit-${{ runner.os }}-${{ hashFiles('.pre-commit-config.yaml') }}
restore-keys: pre-commit-${{ runner.os }}-
- name: Install pre-commit
run: pip install pre-commit
- name: Run pre-commit
run: pre-commit run --all-files --show-diff-on-failure
validate:
name: terraform validate
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Setup Terraform
uses: hashicorp/setup-terraform@v4
with:
terraform_version: "1.15.8"
terraform_wrapper: false
# Root module. init -backend=false installs providers without touching
# remote state; validate then checks the full config against real schemas.
- name: Validate root
run: |
terraform init -backend=false
terraform validate
tflint:
name: tflint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Setup TFLint
uses: terraform-linters/setup-tflint@v6
with:
tflint_version: latest
- name: Init TFLint
run: tflint --init
# Lint the root module and every child module. Report-only for now:
# the repo has pre-existing warnings (unused locals, missing
# required_version in submodules, provider version constraints) that are
# tracked for a follow-up cleanup. Remove `|| true` to make it blocking
# once those are resolved.
- name: Run TFLint
run: |
tflint --chdir=. --recursive || true
trivy:
name: trivy (IaC security scan)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- name: Run Trivy config scan
uses: aquasecurity/trivy-action@v0.36.0
with:
scan-type: config
scan-ref: .
format: table
severity: CRITICAL,HIGH,MEDIUM
# Skip the provider/module cache — scanning downloaded third-party
# modules (AWS eks/vpc/alb/iam) and their example manifests produces
# noise for code we don't own.
skip-dirs: "**/.terraform"
# Report-only for now. The scan surfaces ~19 real findings in our own
# modules (S3 public-access/encryption, ALB SG rules, elasticache
# at-rest encryption) that need proper triage — some are intentional
# (internet-facing ALB) or opinionated (customer-managed KMS). Set to
# "1" to make it blocking once those are addressed/baselined.
exit-code: "0"