-
Notifications
You must be signed in to change notification settings - Fork 0
65 lines (58 loc) · 1.78 KB
/
org-terraform-validate.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
name: Terraform Validate
on:
push:
branches:
- '**'
pull_request:
branches:
- '**'
workflow_call:
workflow_dispatch:
inputs:
terraform_version:
description: 'The version of Terraform to use'
required: true
default: '1.9.0'
type: string
jobs:
verify:
name: Validate Terraform Configuration
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Setup Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: ${{ inputs.terraform_version || '1.9.0' }}
- name: Configure Git for private modules
env:
GH_TOKEN: ${{ secrets.ORG_GITHUB_PAT }}
run: |
git config --global url."https://${GH_TOKEN}@github.com/".insteadOf "https://github.com/"
- name: Initialise with no backend
run: terraform init -backend=false
- name: Validate Terraform
id: validate
run: |
set +e
OUTPUT=$(terraform validate)
CLEAN_OUTPUT=$(echo "$OUTPUT" | sed -r "s/\x1B\[([0-9]{1,2}(;[0-9]{1,2})?)?[m|K]//g")
echo "$CLEAN_OUTPUT"
echo "result=$CLEAN_OUTPUT" >> $GITHUB_OUTPUT
set -e
continue-on-error: true
- name: Create comment
if: github.event_name == 'pull_request'
uses: actions/github-script@v7
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const issue_number = context.issue.number;
const result = `${{ steps.validate.outputs.result }}`;
github.rest.issues.createComment({
owner: context.repo.owner,
repo: context.repo.repo,
issue_number: issue_number,
body: `Terraform validation output:\n\`\`\`\n${result}\n\`\`\``
});