feat: discover and test every module in tf-test workflow - #4
Merged
Merged
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
gberenice
marked this pull request as draft
September 21, 2026 13:52
oycyc
pushed a commit
to masterpointio/github-action-tf-test
that referenced
this pull request
Sep 21, 2026
## What
The action always ran `init` and `test` from the repository root, which
only suits repos holding a single module. Add a `working_directory`
input so monorepos can point each matrix leg at the module under test.
```yaml
- name: Run TF Test
shell: bash
working-directory: ${{ inputs.working_directory }}
run: |
${{ inputs.tf_type }} init
${{ inputs.tf_type }} test
```
## Backwards compatibility
The input defaults to `.`, so every existing caller behaves exactly as
before.
Aqua still resolves `aqua.yaml` from the repository root rather than
from `working_directory`, which keeps pinned CLI versions consistent
across all modules in a monorepo.
## Why now
This unblocks masterpointio/actions#4, which
adds monorepo test discovery to the shared `tf-test` reusable workflow.
That PR already passes `working_directory` but carries a `TODO` on its
action pin, because the input doesn't exist in any release yet. Once
this merges and is released, that pin gets bumped to the new SHA.
## Testing
`actionlint`, `zizmor --persona=pedantic`, `yamllint`, `prettier`, and
`markdownlint` all pass via trunk.
Made with [Cursor](https://cursor.com)
Co-authored-by: Cursor <cursoragent@cursor.com>
gberenice
marked this pull request as ready for review
September 21, 2026 14:24
oycyc
approved these changes
Sep 21, 2026
gberenice
added a commit
that referenced
this pull request
Sep 21, 2026
## Problem `release-please.yaml` here is `workflow_call`-only — it exists for *other* repos to consume. Nothing in this repo ever called it, so release-please has never run and no release was cut when #4 merged. Consumers like `github-action-tf-test` have the caller half; this repo only had the callee half. Two consequences, both fixed: 1. **No caller.** Added `self-release-please.yaml`, triggering on push to `main`. 2. **No GitHub Releases.** `v0.1.0`–`v0.3.0` existed only as lightweight git tags created by hand. Release-please reads the Releases API to find the last version, so it would have ignored those tags and restarted versioning at `1.0.0`. I backfilled releases for all three tags, with `v0.3.0` marked latest, so the next run proposes `v0.4.0`. ## Self-repository syntax The call uses `$/` rather than `./`: ```yaml uses: $/.github/workflows/release-please.yaml ``` [GitHub shipped this in July 2026](https://github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax/). It resolves to the exact running commit with no checkout, and unlike `./` it counts as pinning for policy enforcement — which matters for a repo whose whole purpose is publishing pinned workflows. zizmor's `self-repository` audit recommends it. The alternative, pinning to `masterpointio/actions@<sha>`, would need a bump on every single release. Tradeoff worth flagging: actionlint 1.7.12 predates the syntax and rejects it, hence the scoped `trunk-ignore`. Requires runner 2.336.0+, which GitHub-hosted runners satisfy. If the first run fails, swapping `$/` for `./` is a one-line fallback. ## Follow-up This repo also runs no CI on its own PRs — `lint.yaml` is likewise `workflow_call`-only and there's no `.trunk` config. Separate PR, so a first-time trunk run surfacing pre-existing findings doesn't block this release fix. ## Testing `actionlint`, `zizmor --persona=pedantic`, `yamllint`, and `prettier` pass locally (borrowing a trunk config, since this repo has none). Made with [Cursor](https://cursor.com) Co-authored-by: Cursor <cursoragent@cursor.com>
gberenice
pushed a commit
that referenced
this pull request
Sep 21, 2026
🤖 I have created a release *beep* *boop* --- ## [0.4.0](v0.3.0...v0.4.0) (2026-09-21) ### Features * discover and test every module in tf-test workflow ([#4](#4)) ([5ca743a](5ca743a)) ### Bug Fixes * run release-please on this repo ([#5](#5)) ([fc531db](fc531db)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: masterpointbot[bot] <177651640+masterpointbot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The
tf-testreusable workflow assumed a single module at the repository root, so monorepos had to hand-roll their own aqua +init+teststeps instead of consuming it.discoverjob that finds every directory containing*.tftest.hclfiles and emits them as a JSON array. Both thetests/subdirectory and module-root layouts collapse to the module directory.(tf_type x module)withfail-fast: false, so callers stay zero-config as modules are added.aws_role_arnand theSPACELIFT_*secrets to optional, since they're consumer-specific and not every repo under test touches AWS or Spacelift. Drop the redundantrequired: falselines and describe each secret.masterpointio/github-action-tf-testto v1.1.0, which adds theworking_directoryinput this depends on.Backwards compatibility
Root-level modules report as
.and keep their original job name:Without this,
terraform-spacelift-automation's checks would rename from🧪 tofu testto🧪 tofu test (.)and break any branch protection rules keyed to those names.Dependencies
masterpointio/github-action-tf-test#49 — merged and released as v1.1.0, now pinned here.
Testing
Discovery pipeline verified against
infra-monorepo-template(returns["child-modules/random-pet"]) and against an empty repo (returns[], which skips the test job via theif:guard).actionlint,zizmor --persona=pedantic, andyamllintall pass.Follow-up
infra-monorepo-templateswitches its hand-rolledtest.yamlover to this workflow once it's released.