terraform plan on pr and caddy metrics on localhost since we have alloy now

This commit is contained in:
Rasmus Wejlgaard 2026-05-05 13:29:45 +01:00
parent 9bde71fbf9
commit 2ef2490f77
3 changed files with 72 additions and 20 deletions

View file

@ -20,7 +20,7 @@ jobs:
- name: Install OpenTofu
uses: opentofu/setup-opentofu@v2
with:
tofu_version: latest
tofu_version: 1.9.0
- name: Install SOPS
run: |
@ -71,7 +71,7 @@ jobs:
- name: Install OpenTofu
uses: opentofu/setup-opentofu@v2
with:
tofu_version: latest
tofu_version: 1.9.0
- name: Install SOPS
run: |

View file

@ -3,9 +3,16 @@ name: Validate Terraform
on:
pull_request:
permissions:
contents: read
pull-requests: write
# Requires these repository secrets:
# AGE_SECRET_KEY — age private key for SOPS decryption
jobs:
tofu-validate:
name: tofu validate
plan:
name: tofu plan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
@ -13,7 +20,7 @@ jobs:
- name: Install OpenTofu
uses: opentofu/setup-opentofu@v2
with:
tofu_version: latest
tofu_version: 1.9.0
- name: Install SOPS
run: |
@ -30,18 +37,63 @@ jobs:
echo "Decrypted: $f -> $out"
done
- name: Find and validate Terraform roots
- name: Set backend credentials
working-directory: terraform/
run: |
found=0
for dir in $(find terraform/ -name '*.tf' -printf '%h\n' | sort -u); do
echo "::group::Validating $dir"
cd "$dir"
tofu init -backend=false
tofu validate
cd "$GITHUB_WORKSPACE"
echo "::endgroup::"
found=1
done
if [ "$found" -eq 0 ]; then
echo "No .tf files found — skipping validation."
fi
echo "AWS_ACCESS_KEY_ID=$(yq '.backblaze_keyID' secrets.yaml)" >> "$GITHUB_ENV"
echo "AWS_SECRET_ACCESS_KEY=$(yq '.backblaze_applicationKey' secrets.yaml)" >> "$GITHUB_ENV"
- name: tofu init
working-directory: terraform/
run: tofu init
- name: tofu validate
working-directory: terraform/
run: tofu validate
- name: tofu plan
id: plan
working-directory: terraform/
continue-on-error: true
run: |
set -o pipefail
tofu plan -no-color 2>&1 | tee plan_output.txt
- name: Post plan as PR comment
uses: actions/github-script@v7
with:
script: |
const fs = require('fs');
const raw = fs.readFileSync('terraform/plan_output.txt', 'utf8');
const truncated = raw.length > 65000
? raw.slice(0, 65000) + '\n\n...(output truncated)'
: raw;
const outcome = '${{ steps.plan.outcome }}';
const header = outcome === 'failure' ? '## Terraform Plan — FAILED' : '## Terraform Plan';
const body = `${header}\n\`\`\`\n${truncated}\n\`\`\``;
const { data: comments } = await github.rest.issues.listComments({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
});
const existing = comments.find(c => c.body.startsWith('## Terraform Plan'));
if (existing) {
await github.rest.issues.updateComment({
owner: context.repo.owner,
repo: context.repo.repo,
comment_id: existing.id,
body,
});
} else {
await github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: context.issue.number,
body,
});
}
- name: Fail if plan failed
if: steps.plan.outcome == 'failure'
run: exit 1

View file

@ -6,7 +6,7 @@
#
{
admin 100.67.6.27:2019
admin localhost:2019
metrics {
per_host
}