c80060878a
EXECUTE stage. Authors the remaining 11 L1 module terraform subdirs with the full versions/variables/locals/main/outputs split. Defaults previously hardcoded in the adapter move into locals.tf. Simple single-resource modules (7): - kms-key: aws_kms_key + alias (enable_key_rotation, deletion_window defaults) - ecr: aws_ecr_repository (encryption_configuration from kms_key_arn, image_scanning) - ecs-cluster: aws_ecs_cluster (name default) - iam-role: aws_iam_role + inline_policy (assume_role_policy fallback, ECR/logs policy in locals.tf) - rds: aws_db_instance (storage_encrypted, multi_az, kms_key_arn defaults) - waf: aws_wafv2_web_acl (default_action, visibility_config, dynamic rules) - uptime: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions in locals.tf) Multi-resource modules with intra-refs (4): - vpc: aws_vpc + aws_subnet + aws_internet_gateway + aws_route_table (CIDR derivation in locals.tf) - ecs-service: aws_ecs_task_definition + aws_ecs_service (Fargate compat, container_definitions, network_config in locals.tf) - alb: aws_lb + aws_lb_target_group + aws_lb_listener (subnet/security_group list derivation in locals.tf) - cloudfront: aws_cloudfront_distribution + aws_cloudfront_origin_access_control (OAC defaults in locals.tf) Registry: terraform_dir added to all 11 remaining entries. Adapter fix: stack output format uses separate 'from' + 'output' fields (not 'from': 'rid.output'). Fixed _emit_root_output to read both fields. 6 previously-skipped tests unblocked (run_platform.sh --check-only now resolves static-assets.yml through the new module-assembled adapter). Removed skip markers. Fixed test assertion (aws_s3_bucket → module). Regression: 461 passed, 0 skipped, 5 deselected (slow). All 12 modules pass run_primitive_plan.sh --check-only. All 12 terraform/ subdirs pass terraform init + validate standalone. ---ci--- project: acdl phase: P56b milestone: v1.11 status: execute ---/ci---
67 lines
2.4 KiB
Python
67 lines
2.4 KiB
Python
import json
|
|
import os
|
|
import subprocess
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
ROOT = Path(__file__).resolve().parent.parent
|
|
|
|
|
|
class TestPipelineIntegration:
|
|
def test_load_stack_and_adapt_offline(self, tmp_path):
|
|
stack = json.load(open(ROOT / "modules/l1/s3/instance.json"))
|
|
assert stack["stack"]["name"] == "s3"
|
|
|
|
sys.path.insert(0, str(ROOT))
|
|
from adapters.terraform.adapter import adapt
|
|
out_dir = str(tmp_path / "tf")
|
|
adapt(stack, out_dir)
|
|
|
|
assert os.path.isfile(os.path.join(out_dir, "main.tf"))
|
|
assert os.path.isfile(os.path.join(out_dir, "terraform.tf"))
|
|
assert os.path.isfile(os.path.join(out_dir, "providers.tf"))
|
|
|
|
main_tf = open(os.path.join(out_dir, "main.tf")).read()
|
|
assert 'module "s3"' in main_tf
|
|
assert "acdl-spike-bucket" in main_tf
|
|
|
|
def test_confidence_signal_with_adapted_tf(self):
|
|
sys.path.insert(0, str(ROOT))
|
|
from core.confidence_signal import compute
|
|
|
|
inputs = {
|
|
"policy": [{"result": "pass"}],
|
|
"validation": {"schema": True, "stack_resolved": True,
|
|
"tf_validated": True, "tf_planned": True},
|
|
"freshness": {"age_days": 0, "max_age_days": 7},
|
|
"source": {"submitter": "test", "commit_sha": "test-sha"},
|
|
"history": {"prior_rollbacks": 0, "prior_policy_fails": 0},
|
|
"nfrs": {"conformance": None},
|
|
}
|
|
sig = compute("integration-test", "dev", inputs)
|
|
assert sig.band == "pass"
|
|
assert sig.score >= 0.50
|
|
|
|
def test_run_platform_check_only(self):
|
|
result = subprocess.run(
|
|
["bash", str(ROOT / "scripts/run_platform.sh"), "--check-only"],
|
|
capture_output=True, text=True, cwd=str(ROOT),
|
|
timeout=30,
|
|
)
|
|
assert result.returncode == 0, f"stdout: {result.stdout}\nstderr: {result.stderr}"
|
|
assert "PLATFORM CHECK OK" in result.stdout
|
|
|
|
def test_run_platform_check_only_no_aws_creds(self):
|
|
env = os.environ.copy()
|
|
env.pop("AWS_ACCESS_KEY_ID", None)
|
|
env.pop("AWS_SECRET_ACCESS_KEY", None)
|
|
env.pop("AWS_DEFAULT_REGION", None)
|
|
result = subprocess.run(
|
|
["bash", str(ROOT / "scripts/run_platform.sh"), "--check-only"],
|
|
capture_output=True, text=True, cwd=str(ROOT), env=env,
|
|
timeout=30,
|
|
)
|
|
assert result.returncode == 0
|
|
assert "PLATFORM CHECK OK" in result.stdout |