diff --git a/.gitea/workflows/terraform.yml b/.gitea/workflows/terraform.yml
index b9ac653..69f8e2e 100644
--- a/.gitea/workflows/terraform.yml
+++ b/.gitea/workflows/terraform.yml
@@ -29,28 +29,18 @@ jobs:
validate:
name: Validate
runs-on: self-hosted
+ container:
+ image: gitea.arnodo.fr/damien/terraform-ci:latest
steps:
- name: Checkout
uses: actions/checkout@v4
- - name: Setup Terraform
- uses: hashicorp/setup-terraform@v3
- with:
- terraform_version: "1.9"
-
- - name: Setup TFLint
- uses: terraform-linters/setup-tflint@v4
-
- name: Terraform Format Check
id: fmt
run: terraform fmt -check -recursive -diff
working-directory: ${{ env.TF_WORKING_DIR }}
continue-on-error: true
- - name: TFLint Init
- run: tflint --init
- working-directory: ${{ env.TF_WORKING_DIR }}
-
- name: TFLint
id: lint
run: tflint --recursive --format compact
@@ -89,6 +79,8 @@ jobs:
plan:
name: Plan
runs-on: self-hosted
+ container:
+ image: gitea.arnodo.fr/damien/terraform-ci:latest
needs: validate
outputs:
plan_exitcode: ${{ steps.plan.outputs.exitcode }}
@@ -96,11 +88,6 @@ jobs:
- name: Checkout
uses: actions/checkout@v4
- - name: Setup Terraform
- uses: hashicorp/setup-terraform@v3
- with:
- terraform_version: "1.9"
-
- name: Terraform Init
run: terraform init -input=false
working-directory: ${{ env.TF_WORKING_DIR }}
@@ -108,16 +95,24 @@ jobs:
- name: Terraform Plan
id: plan
run: |
+ set +e
terraform plan -input=false -no-color -detailed-exitcode -out=tfplan 2>&1 | tee plan_output.txt
- echo "exitcode=$?" >> $GITHUB_OUTPUT
+ EXITCODE=$?
+ echo "exitcode=${EXITCODE}" >> $GITHUB_OUTPUT
+ # Exit 0 for no changes, exit 2 for changes - both are OK
+ if [ $EXITCODE -eq 1 ]; then
+ exit 1
+ fi
+ exit 0
working-directory: ${{ env.TF_WORKING_DIR }}
- continue-on-error: true
- name: Upload Plan
uses: actions/upload-artifact@v4
with:
name: tfplan
- path: ${{ env.TF_WORKING_DIR }}/tfplan
+ path: |
+ ${{ env.TF_WORKING_DIR }}/tfplan
+ ${{ env.TF_WORKING_DIR }}/plan_output.txt
retention-days: 7
- name: Plan Summary
@@ -125,81 +120,74 @@ jobs:
run: |
echo "## Terraform Plan" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
+ echo "**Exit code:** \`${{ steps.plan.outputs.exitcode }}\`" >> $GITHUB_STEP_SUMMARY
+ echo "- \`0\` = No changes" >> $GITHUB_STEP_SUMMARY
+ echo "- \`2\` = Changes detected" >> $GITHUB_STEP_SUMMARY
+ echo "" >> $GITHUB_STEP_SUMMARY
echo '```' >> $GITHUB_STEP_SUMMARY
cat plan_output.txt >> $GITHUB_STEP_SUMMARY
echo '```' >> $GITHUB_STEP_SUMMARY
working-directory: ${{ env.TF_WORKING_DIR }}
- name: Comment PR with Plan
- if: github.event_name == 'pull_request'
- uses: actions/github-script@v7
- with:
- script: |
- const fs = require('fs');
- const plan = fs.readFileSync('${{ env.TF_WORKING_DIR }}/plan_output.txt', 'utf8');
- const maxLength = 60000;
- const truncated = plan.length > maxLength
- ? plan.substring(0, maxLength) + '\n... (truncated)'
- : plan;
-
- const body = `## 🔍 Terraform Plan
-
-
- Click to expand
-
- \`\`\`hcl
- ${truncated}
- \`\`\`
-
-
-
- **Exit code:** \`${{ steps.plan.outputs.exitcode }}\`
- - \`0\` = No changes
- - \`1\` = Error
- - \`2\` = Changes detected
- `;
-
- github.rest.issues.createComment({
- issue_number: context.issue.number,
- owner: context.repo.owner,
- repo: context.repo.repo,
- body: body
- });
-
- - name: Check Plan Status
- if: steps.plan.outputs.exitcode == '1'
- run: exit 1
+ if: gitea.event_name == 'pull_request'
+ env:
+ GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
+ run: |
+ PLAN_OUTPUT=$(cat plan_output.txt | head -c 60000)
+ COMMENT_BODY=$(cat <
+ Click to expand plan output
+
+ \`\`\`hcl
+ ${PLAN_OUTPUT}
+ \`\`\`
+
+
+ EOF
+ )
+
+ # Post comment via Gitea API
+ curl -s -X POST \
+ -H "Authorization: token ${GITEA_TOKEN}" \
+ -H "Content-Type: application/json" \
+ -d "$(jq -n --arg body "$COMMENT_BODY" '{body: $body}')" \
+ "${{ gitea.server_url }}/api/v1/repos/${{ gitea.repository }}/issues/${{ gitea.event.pull_request.number }}/comments"
+ working-directory: ${{ env.TF_WORKING_DIR }}
# ===========================================================================
- # Apply - Runs on push to dev OR after PR merge
+ # Apply - Runs on push to dev only (when changes detected)
# ===========================================================================
apply:
name: Apply
runs-on: self-hosted
+ container:
+ image: gitea.arnodo.fr/damien/terraform-ci:latest
needs: plan
if: |
- (github.event_name == 'push' && github.ref == 'refs/heads/dev') &&
+ gitea.event_name == 'push' &&
+ gitea.ref == 'refs/heads/dev' &&
needs.plan.outputs.plan_exitcode == '2'
- environment: production
steps:
- name: Checkout
uses: actions/checkout@v4
- - name: Setup Terraform
- uses: hashicorp/setup-terraform@v3
- with:
- terraform_version: "1.9"
-
- - name: Terraform Init
- run: terraform init -input=false
- working-directory: ${{ env.TF_WORKING_DIR }}
-
- name: Download Plan
uses: actions/download-artifact@v4
with:
name: tfplan
path: ${{ env.TF_WORKING_DIR }}
+ - name: Terraform Init
+ run: terraform init -input=false
+ working-directory: ${{ env.TF_WORKING_DIR }}
+
- name: Terraform Apply
run: terraform apply -input=false -auto-approve tfplan
working-directory: ${{ env.TF_WORKING_DIR }}