-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ci: configure terraform pipeline (#8)
* ci: configure tfvars file * fix the use of local env variables * fix environment variable * copilot said this is the right way * okay, now that's to verbose * vai assim mesmo * fix workflow * fix tfvars file * update default variables * trigger new plan * add BMB_MYSQL_DATABASE
- Loading branch information
1 parent
cf0450a
commit 04bcd21
Showing
6 changed files
with
200 additions
and
25 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -2,6 +2,7 @@ name: 'Terraform build' | |
|
||
on: | ||
push: | ||
branches: [ "main" ] | ||
pull_request: | ||
|
||
env: | ||
|
@@ -15,6 +16,27 @@ permissions: | |
|
||
jobs: | ||
|
||
terraform-settings: | ||
name: "Terraform Settings" | ||
runs-on: ubuntu-latest | ||
|
||
steps: | ||
- name: Config | ||
run: | | ||
cat <<EOF > db.auto.tfvars | ||
cluster_name = "${{ vars.BMB_MYSQL_CLUSTER }}" | ||
database_name = "${{ vars.BMB_MYSQL_DATABASE }}" | ||
vpc_name = "${{ vars.BMB_EKS_CLUSTER_VPC }}" | ||
username = "${{ secrets.BMB_MYSQL_USER }}" | ||
password = "${{ secrets.BMB_MYSQL_PASSWORD }}" | ||
EOF | ||
- name: Upload Configuration | ||
uses: actions/upload-artifact@v4 | ||
with: | ||
name: database-config | ||
path: db.auto.tfvars | ||
|
||
test: | ||
name: 'Test' | ||
runs-on: ubuntu-latest | ||
|
@@ -28,6 +50,11 @@ jobs: | |
- name: Checkout | ||
uses: actions/checkout@v4 | ||
|
||
- name: Download Configuration | ||
uses: actions/download-artifact@v4 | ||
with: | ||
name: database-config | ||
|
||
- name: Setup Terraform | ||
uses: hashicorp/setup-terraform@v1 | ||
with: | ||
|
@@ -41,12 +68,11 @@ jobs: | |
run: terraform test | ||
|
||
sonarcloud: | ||
needs: [test] | ||
if: github.event_name == 'pull_request' || github.ref == 'refs/heads/main' | ||
name: SonarCloud | ||
runs-on: ubuntu-latest | ||
steps: | ||
- uses: actions/checkout@v3 | ||
- uses: actions/checkout@v4 | ||
with: | ||
fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis | ||
- name: SonarCloud Scan | ||
|
@@ -55,8 +81,85 @@ jobs: | |
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} # Needed to get PR information, if any | ||
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} | ||
|
||
|
||
terraform-plan: | ||
needs: [test, terraform-settings] | ||
if: github.event_name == 'pull_request' | ||
environment: dev | ||
name: "Terraform Plan" | ||
runs-on: ubuntu-latest | ||
permissions: | ||
contents: read | ||
pull-requests: write | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v4 | ||
|
||
- name: Download Configuration | ||
uses: actions/download-artifact@v4 | ||
with: | ||
name: database-config | ||
|
||
- name: Upload Configuration | ||
uses: hashicorp/tfc-workflows-github/actions/[email protected] | ||
id: plan-upload | ||
with: | ||
workspace: ${{ env.TF_WORKSPACE }} | ||
directory: ${{ env.CONFIG_DIRECTORY }} | ||
speculative: true | ||
|
||
- name: Create Plan Run | ||
uses: hashicorp/tfc-workflows-github/actions/[email protected] | ||
id: plan-run | ||
with: | ||
workspace: ${{ env.TF_WORKSPACE }} | ||
configuration_version: ${{ steps.plan-upload.outputs.configuration_version_id }} | ||
plan_only: true | ||
|
||
- name: Get Plan Output | ||
uses: hashicorp/tfc-workflows-github/actions/[email protected] | ||
id: plan-output | ||
with: | ||
plan: ${{ fromJSON(steps.plan-run.outputs.payload).data.relationships.plan.data.id }} | ||
|
||
- name: Update PR | ||
uses: actions/github-script@v7 | ||
id: plan-comment | ||
with: | ||
github-token: ${{ secrets.GITHUB_TOKEN }} | ||
script: | | ||
// 1. Retrieve existing bot comments for the PR | ||
const { data: comments } = await github.rest.issues.listComments({ | ||
owner: context.repo.owner, | ||
repo: context.repo.repo, | ||
issue_number: context.issue.number, | ||
}); | ||
const botComment = comments.find(comment => { | ||
return comment.user.type === 'Bot' && comment.body.includes('Terraform Cloud Plan Output') | ||
}); | ||
const output = `#### Terraform Cloud Plan Output | ||
\`\`\` | ||
Plan: ${{ steps.plan-output.outputs.add }} to add, ${{ steps.plan-output.outputs.change }} to change, ${{ steps.plan-output.outputs.destroy }} to destroy. | ||
\`\`\` | ||
[Terraform Cloud Plan](${{ steps.plan-run.outputs.run_link }}) | ||
`; | ||
// 3. Delete previous comment so PR timeline makes sense | ||
if (botComment) { | ||
github.rest.issues.deleteComment({ | ||
owner: context.repo.owner, | ||
repo: context.repo.repo, | ||
comment_id: botComment.id, | ||
}); | ||
} | ||
github.rest.issues.createComment({ | ||
issue_number: context.issue.number, | ||
owner: context.repo.owner, | ||
repo: context.repo.repo, | ||
body: output | ||
}); | ||
deploy: | ||
needs: [test] | ||
needs: [test, terraform-settings] | ||
if: github.ref == 'refs/heads/main' | ||
name: "Terraform Apply" | ||
runs-on: ubuntu-latest | ||
|
@@ -65,7 +168,12 @@ jobs: | |
contents: read | ||
steps: | ||
- name: Checkout | ||
uses: actions/checkout@v3 | ||
uses: actions/checkout@v4 | ||
|
||
- name: Download Configuration | ||
uses: actions/download-artifact@v4 | ||
with: | ||
name: database-config | ||
|
||
- name: Upload Configuration | ||
uses: hashicorp/tfc-workflows-github/actions/[email protected] | ||
|
@@ -81,11 +189,10 @@ jobs: | |
workspace: ${{ env.TF_WORKSPACE }} | ||
configuration_version: ${{ steps.apply-upload.outputs.configuration_version_id }} | ||
message: "Plan Run from GitHub Actions CI ${{ github.sha }}" | ||
TF_VAR_vpc_name: "\"teste\"" | ||
|
||
- name: Apply | ||
uses: hashicorp/tfc-workflows-github/actions/[email protected] | ||
if: fromJSON(steps.apply-run.outputs.payload).data.attributes.actions.IsConfirmable && false | ||
if: fromJSON(steps.apply-run.outputs.payload).data.attributes.actions.IsConfirmable && ${{ vars.TF_AUTO_APPROVE == 'true' }} | ||
id: apply | ||
with: | ||
run: ${{ steps.apply-run.outputs.run_id }} | ||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,57 @@ | ||
use techchallenge; | ||
|
||
create table IF NOT EXISTS Customers | ||
( | ||
Id char(36) not null | ||
primary key, | ||
Cpf varchar(11) not null, | ||
Name varchar(100) null, | ||
Email varchar(100) null | ||
); | ||
|
||
|
||
create table IF NOT EXISTS Products | ||
( | ||
Id char(36) not null comment 'product id' | ||
primary key, | ||
Name varchar(100) not null, | ||
Description varchar(200) not null, | ||
Category int not null, | ||
Price decimal(10,2) not null, | ||
Images varchar(1000) null | ||
); | ||
|
||
|
||
create table IF NOT EXISTS Orders | ||
( | ||
Id char(36) not null, | ||
CustomerId char(36) null, | ||
PaymentId char(36) null, | ||
Status int not null, | ||
Created datetime null, | ||
Updated datetime null, | ||
TrackingCode varchar(7) null | ||
); | ||
|
||
|
||
create table IF NOT EXISTS OrderItems | ||
( | ||
OrderId char(36) not null, | ||
ProductId char(36) not null, | ||
ProductName varchar(200) not null, | ||
UnitPrice decimal not null, | ||
Quantity int null | ||
); | ||
|
||
create table IF NOT EXISTS Payments | ||
( | ||
Id char(36) not null, | ||
OrderId char(36) not null, | ||
Status int not null, | ||
Created datetime null, | ||
Updated datetime null, | ||
PaymentType int not null, | ||
ExternalReference varchar(36) not null, | ||
Amount decimal(10,2) not null, | ||
PRIMARY KEY (Id, OrderId) | ||
); |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters