From 60db1e32cb6f6ea41df7a8dc6964eb81f1103c1b Mon Sep 17 00:00:00 2001 From: WasathTheekshana Date: Fri, 10 May 2024 11:00:18 +0530 Subject: [PATCH] ci: Terraform cloud pipeline --- .github/workflows/tfcloud.yaml | 49 ++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 .github/workflows/tfcloud.yaml diff --git a/.github/workflows/tfcloud.yaml b/.github/workflows/tfcloud.yaml new file mode 100644 index 0000000..575ef04 --- /dev/null +++ b/.github/workflows/tfcloud.yaml @@ -0,0 +1,49 @@ +name: "Terraform ☁️" + +on: + push: + branches: ["main"] + pull_request: + +permissions: + contents: read + +jobs: + terraform: + name: "Terraform" + runs-on: ubuntu-latest + environment: production + + # Use the Bash shell regardless whether the GitHub Actions runner is ubuntu-latest, macos-latest, or windows-latest + defaults: + run: + shell: bash + + steps: + # Checkout the repository to the GitHub Actions runner + - name: Checkout + uses: actions/checkout@v3 + + # Install the latest version of Terraform CLI and configure the Terraform CLI configuration file with a Terraform Cloud user API token + - name: Setup Terraform + uses: hashicorp/setup-terraform@v1 + with: + cli_config_credentials_token: ${{ secrets.TF_API_TOKEN }} + + # Initialize a new or existing Terraform working directory by creating initial files, loading any remote state, downloading modules, etc. + - name: Terraform Init + run: terraform init + + # Checks that all Terraform configuration files adhere to a canonical format + - name: Terraform Format + run: terraform fmt -check + + # Generates an execution plan for Terraform + - name: Terraform Plan + run: terraform plan -input=false + + # On push to "main", build or change infrastructure according to Terraform configuration files + # Note: It is recommended to set up a required "strict" status check in your repository for "Terraform Cloud". See the documentation on "strict" required status checks for more information: https://help.github.com/en/github/administering-a-repository/types-of-required-status-checks + - name: Terraform Apply + if: github.ref == 'refs/heads/"main"' && github.event_name == 'push' + run: terraform apply -auto-approve -input=false