Skip to content

Merge pull request #21 from codebytes/dependabot/github_actions/actio… #47

Merge pull request #21 from codebytes/dependabot/github_actions/actio…

Merge pull request #21 from codebytes/dependabot/github_actions/actio… #47

Workflow file for this run

name: 'Terraform'
on:
push:
branches: [ "main" ]
workflow_dispatch:
permissions:
id-token: write
contents: read
jobs:
dev-state-store:
name: 'Dev State Store'
runs-on: ubuntu-latest
environment: dev
env:
ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }}
ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }}
TF_STATE_STORAGEACCT: ${{ secrets.TF_STATE_STORAGEACCT }}
TF_STATE_CONTAINER: ${{ secrets.TF_STATE_CONTAINER }}
TF_STATE_RG: ${{ secrets.TF_STATE_RG }}
steps:
- name: Azure Login
uses: azure/login@v2
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
- name: Azure CLI script
uses: azure/CLI@v2
with:
inlineScript: |
az group create --name $TF_STATE_RG --location eastus
az storage account create --resource-group $TF_STATE_RG --name $TF_STATE_STORAGEACCT --sku Standard_LRS --encryption-services blob
az storage container create --name $TF_STATE_CONTAINER --account-name $TF_STATE_STORAGEACCT
dev:
name: 'Dev Terraform'
runs-on: ubuntu-latest
environment: dev
needs: dev-state-store
# Use the Bash shell regardless whether the GitHub Actions runner is ubuntu-latest, macos-latest, or windows-latest
defaults:
run:
shell: bash
working-directory: example/dev
env:
ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }}
ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }}
ARM_USE_OIDC: true
TF_STATE_STORAGEACCT: ${{ secrets.TF_STATE_STORAGEACCT }}
TF_STATE_CONTAINER: ${{ secrets.TF_STATE_CONTAINER }}
TF_STATE_RG: ${{ secrets.TF_STATE_RG }}
TF_VAR_environment: dev
steps:
# Checkout the repository to the GitHub Actions runner
- name: Checkout
uses: actions/checkout@v4
# Install the latest version of Terraform CLI and configure the Terraform CLI configuration file with a Terraform Cloud user API token
- name: Setup Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: latest # optional, default is latest
# Initialize a new or existing Terraform working directory by creating initial files, loading any remote state, downloading modules, etc.
- name: Terraform Init
run: |
terraform init \
-backend-config="storage_account_name=$TF_STATE_STORAGEACCT" \
-backend-config="container_name=$TF_STATE_CONTAINER" \
-backend-config="resource_group_name=$TF_STATE_RG" \
-backend-config="key=$TF_VAR_environment.terraform.tfstate"
# Checks that all Terraform configuration files adhere to a canonical format
- name: Terraform Format
run: terraform fmt -check
# Generates an execution plan for Terraform
- name: Terraform Plan
run: terraform plan -input=false
# On push to "main", build or change infrastructure according to Terraform configuration files
# Note: It is recommended to set up a required "strict" status check in your repository for "Terraform Cloud". See the documentation on "strict" required status checks for more information: https://help.github.com/en/github/administering-a-repository/types-of-required-status-checks
- name: Terraform Apply
# if: github.ref == 'refs/heads/"main"' && github.event_name == 'push'
run: terraform apply -auto-approve -input=false
prod-state-store:
name: 'prod State Store'
runs-on: ubuntu-latest
environment: prod
needs: dev
env:
ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }}
ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }}
TF_STATE_STORAGEACCT: ${{ secrets.TF_STATE_STORAGEACCT }}
TF_STATE_CONTAINER: ${{ secrets.TF_STATE_CONTAINER }}
TF_STATE_RG: ${{ secrets.TF_STATE_RG }}
steps:
- name: Azure Login
uses: azure/login@v2
with:
client-id: ${{ secrets.AZURE_CLIENT_ID }}
tenant-id: ${{ secrets.AZURE_TENANT_ID }}
subscription-id: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
- name: Azure CLI script
uses: azure/CLI@v2
with:
inlineScript: |
az group create --name $TF_STATE_RG --location eastus
az storage account create --resource-group $TF_STATE_RG --name $TF_STATE_STORAGEACCT --sku Standard_LRS --encryption-services blob
az storage container create --name $TF_STATE_CONTAINER --account-name $TF_STATE_STORAGEACCT
prod:
name: 'prod Terraform'
runs-on: ubuntu-latest
environment: prod
needs: prod-state-store
# Use the Bash shell regardless whether the GitHub Actions runner is ubuntu-latest, macos-latest, or windows-latest
defaults:
run:
shell: bash
working-directory: example/prod
env:
ARM_SUBSCRIPTION_ID: ${{ secrets.AZURE_SUBSCRIPTION_ID }}
ARM_CLIENT_ID: ${{ secrets.AZURE_CLIENT_ID }}
ARM_TENANT_ID: ${{ secrets.AZURE_TENANT_ID }}
ARM_USE_OIDC: true
TF_STATE_STORAGEACCT: ${{ secrets.TF_STATE_STORAGEACCT }}
TF_STATE_CONTAINER: ${{ secrets.TF_STATE_CONTAINER }}
TF_STATE_RG: ${{ secrets.TF_STATE_RG }}
TF_VAR_environment: prod
steps:
# Checkout the repository to the GitHub Actions runner
- name: Checkout
uses: actions/checkout@v4
# Install the latest version of Terraform CLI and configure the Terraform CLI configuration file with a Terraform Cloud user API token
- name: Setup Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: latest # optional, default is latest
# Initialize a new or existing Terraform working directory by creating initial files, loading any remote state, downloading modules, etc.
- name: Terraform Init
run: |
terraform init \
-backend-config="storage_account_name=$TF_STATE_STORAGEACCT" \
-backend-config="container_name=$TF_STATE_CONTAINER" \
-backend-config="resource_group_name=$TF_STATE_RG" \
-backend-config="key=$TF_VAR_environment.terraform.tfstate"
# Checks that all Terraform configuration files adhere to a canonical format
- name: Terraform Format
run: terraform fmt -check
# Generates an execution plan for Terraform
- name: Terraform Plan
run: terraform plan -input=false
# On push to "main", build or change infrastructure according to Terraform configuration files
# Note: It is recommended to set up a required "strict" status check in your repository for "Terraform Cloud". See the documentation on "strict" required status checks for more information: https://help.github.com/en/github/administering-a-repository/types-of-required-status-checks
- name: Terraform Apply
# if: github.ref == 'refs/heads/"main"' && github.event_name == 'push'
run: terraform apply -auto-approve -input=false