diff --git a/.gitea/workflows/terraform.yml b/.gitea/workflows/terraform.yml index b9ac653..69f8e2e 100644 --- a/.gitea/workflows/terraform.yml +++ b/.gitea/workflows/terraform.yml @@ -29,28 +29,18 @@ jobs: validate: name: Validate runs-on: self-hosted + container: + image: gitea.arnodo.fr/damien/terraform-ci:latest steps: - name: Checkout uses: actions/checkout@v4 - - name: Setup Terraform - uses: hashicorp/setup-terraform@v3 - with: - terraform_version: "1.9" - - - name: Setup TFLint - uses: terraform-linters/setup-tflint@v4 - - name: Terraform Format Check id: fmt run: terraform fmt -check -recursive -diff working-directory: ${{ env.TF_WORKING_DIR }} continue-on-error: true - - name: TFLint Init - run: tflint --init - working-directory: ${{ env.TF_WORKING_DIR }} - - name: TFLint id: lint run: tflint --recursive --format compact @@ -89,6 +79,8 @@ jobs: plan: name: Plan runs-on: self-hosted + container: + image: gitea.arnodo.fr/damien/terraform-ci:latest needs: validate outputs: plan_exitcode: ${{ steps.plan.outputs.exitcode }} @@ -96,11 +88,6 @@ jobs: - name: Checkout uses: actions/checkout@v4 - - name: Setup Terraform - uses: hashicorp/setup-terraform@v3 - with: - terraform_version: "1.9" - - name: Terraform Init run: terraform init -input=false working-directory: ${{ env.TF_WORKING_DIR }} @@ -108,16 +95,24 @@ jobs: - name: Terraform Plan id: plan run: | + set +e terraform plan -input=false -no-color -detailed-exitcode -out=tfplan 2>&1 | tee plan_output.txt - echo "exitcode=$?" >> $GITHUB_OUTPUT + EXITCODE=$? + echo "exitcode=${EXITCODE}" >> $GITHUB_OUTPUT + # Exit 0 for no changes, exit 2 for changes - both are OK + if [ $EXITCODE -eq 1 ]; then + exit 1 + fi + exit 0 working-directory: ${{ env.TF_WORKING_DIR }} - continue-on-error: true - name: Upload Plan uses: actions/upload-artifact@v4 with: name: tfplan - path: ${{ env.TF_WORKING_DIR }}/tfplan + path: | + ${{ env.TF_WORKING_DIR }}/tfplan + ${{ env.TF_WORKING_DIR }}/plan_output.txt retention-days: 7 - name: Plan Summary @@ -125,81 +120,74 @@ jobs: run: | echo "## Terraform Plan" >> $GITHUB_STEP_SUMMARY echo "" >> $GITHUB_STEP_SUMMARY + echo "**Exit code:** \`${{ steps.plan.outputs.exitcode }}\`" >> $GITHUB_STEP_SUMMARY + echo "- \`0\` = No changes" >> $GITHUB_STEP_SUMMARY + echo "- \`2\` = Changes detected" >> $GITHUB_STEP_SUMMARY + echo "" >> $GITHUB_STEP_SUMMARY echo '```' >> $GITHUB_STEP_SUMMARY cat plan_output.txt >> $GITHUB_STEP_SUMMARY echo '```' >> $GITHUB_STEP_SUMMARY working-directory: ${{ env.TF_WORKING_DIR }} - name: Comment PR with Plan - if: github.event_name == 'pull_request' - uses: actions/github-script@v7 - with: - script: | - const fs = require('fs'); - const plan = fs.readFileSync('${{ env.TF_WORKING_DIR }}/plan_output.txt', 'utf8'); - const maxLength = 60000; - const truncated = plan.length > maxLength - ? plan.substring(0, maxLength) + '\n... (truncated)' - : plan; - - const body = `## 🔍 Terraform Plan - -
- Click to expand - - \`\`\`hcl - ${truncated} - \`\`\` - -
- - **Exit code:** \`${{ steps.plan.outputs.exitcode }}\` - - \`0\` = No changes - - \`1\` = Error - - \`2\` = Changes detected - `; - - github.rest.issues.createComment({ - issue_number: context.issue.number, - owner: context.repo.owner, - repo: context.repo.repo, - body: body - }); - - - name: Check Plan Status - if: steps.plan.outputs.exitcode == '1' - run: exit 1 + if: gitea.event_name == 'pull_request' + env: + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} + run: | + PLAN_OUTPUT=$(cat plan_output.txt | head -c 60000) + COMMENT_BODY=$(cat < + Click to expand plan output + + \`\`\`hcl + ${PLAN_OUTPUT} + \`\`\` + + + EOF + ) + + # Post comment via Gitea API + curl -s -X POST \ + -H "Authorization: token ${GITEA_TOKEN}" \ + -H "Content-Type: application/json" \ + -d "$(jq -n --arg body "$COMMENT_BODY" '{body: $body}')" \ + "${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/issues/${{ gitea.event.pull_request.number }}/comments" + working-directory: ${{ env.TF_WORKING_DIR }} # =========================================================================== - # Apply - Runs on push to dev OR after PR merge + # Apply - Runs on push to dev only (when changes detected) # =========================================================================== apply: name: Apply runs-on: self-hosted + container: + image: gitea.arnodo.fr/damien/terraform-ci:latest needs: plan if: | - (github.event_name == 'push' && github.ref == 'refs/heads/dev') && + gitea.event_name == 'push' && + gitea.ref == 'refs/heads/dev' && needs.plan.outputs.plan_exitcode == '2' - environment: production steps: - name: Checkout uses: actions/checkout@v4 - - name: Setup Terraform - uses: hashicorp/setup-terraform@v3 - with: - terraform_version: "1.9" - - - name: Terraform Init - run: terraform init -input=false - working-directory: ${{ env.TF_WORKING_DIR }} - - name: Download Plan uses: actions/download-artifact@v4 with: name: tfplan path: ${{ env.TF_WORKING_DIR }} + - name: Terraform Init + run: terraform init -input=false + working-directory: ${{ env.TF_WORKING_DIR }} + - name: Terraform Apply run: terraform apply -input=false -auto-approve tfplan working-directory: ${{ env.TF_WORKING_DIR }}