Skip to content

feat: discover and test every module in tf-test workflow - #4

Merged
gberenice merged 2 commits into
mainfrom
feat/tf-test-monorepo
Sep 21, 2026
Merged

gberenice merged 2 commits into
mainfrom
feat/tf-test-monorepo

Conversation

@gberenice

@gberenice gberenice commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

What

The tf-test reusable workflow assumed a single module at the repository root, so monorepos had to hand-roll their own aqua + init + test steps instead of consuming it.

  • Add a discover job that finds every directory containing *.tftest.hcl files and emits them as a JSON array. Both the tests/ subdirectory and module-root layouts collapse to the module directory.
  • Fan the test job out across (tf_type x module) with fail-fast: false, so callers stay zero-config as modules are added.
  • Relax aws_role_arn and the SPACELIFT_* secrets to optional, since they're consumer-specific and not every repo under test touches AWS or Spacelift. Drop the redundant required: false lines and describe each secret.
  • Add job timeouts (5m discover, 30m test).
  • Bump masterpointio/github-action-tf-test to v1.1.0, which adds the working_directory input this depends on.

Backwards compatibility

Root-level modules report as . and keep their original job name:

name: 🧪 ${{ matrix.tf }} test${{ matrix.module != '.' && format(' ({0})', matrix.module) || '' }}

Without this, terraform-spacelift-automation's checks would rename from 🧪 tofu test to 🧪 tofu test (.) and break any branch protection rules keyed to those names.

Dependencies

masterpointio/github-action-tf-test#49 — merged and released as v1.1.0, now pinned here.

Testing

Discovery pipeline verified against infra-monorepo-template (returns ["child-modules/random-pet"]) and against an empty repo (returns [], which skips the test job via the if: guard). actionlint, zizmor --persona=pedantic, and yamllint all pass.

Follow-up

infra-monorepo-template switches its hand-rolled test.yaml over to this workflow once it's released.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c2486edb-bede-40dd-928f-f74bcbb0bd1e


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gberenice
gberenice marked this pull request as draft September 21, 2026 13:52
oycyc pushed a commit to masterpointio/github-action-tf-test that referenced this pull request Sep 21, 2026
## What

The action always ran `init` and `test` from the repository root, which
only suits repos holding a single module. Add a `working_directory`
input so monorepos can point each matrix leg at the module under test.

```yaml
- name: Run TF Test
  shell: bash
  working-directory: ${{ inputs.working_directory }}
  run: |
    ${{ inputs.tf_type }} init
    ${{ inputs.tf_type }} test
```

## Backwards compatibility

The input defaults to `.`, so every existing caller behaves exactly as
before.

Aqua still resolves `aqua.yaml` from the repository root rather than
from `working_directory`, which keeps pinned CLI versions consistent
across all modules in a monorepo.

## Why now

This unblocks masterpointio/actions#4, which
adds monorepo test discovery to the shared `tf-test` reusable workflow.
That PR already passes `working_directory` but carries a `TODO` on its
action pin, because the input doesn't exist in any release yet. Once
this merges and is released, that pin gets bumped to the new SHA.

## Testing

`actionlint`, `zizmor --persona=pedantic`, `yamllint`, `prettier`, and
`markdownlint` all pass via trunk.

Made with [Cursor](https://cursor.com)
Co-authored-by: Cursor <cursoragent@cursor.com>
@gberenice
gberenice marked this pull request as ready for review September 21, 2026 14:24
@gberenice
gberenice merged commit 5ca743a into main Sep 21, 2026
1 check passed
@gberenice
gberenice deleted the feat/tf-test-monorepo branch September 21, 2026 15:51
gberenice added a commit that referenced this pull request Sep 21, 2026
## Problem

`release-please.yaml` here is `workflow_call`-only — it exists for
*other* repos to consume. Nothing in this repo ever called it, so
release-please has never run and no release was cut when #4 merged.

Consumers like `github-action-tf-test` have the caller half; this repo
only had the callee half.

Two consequences, both fixed:

1. **No caller.** Added `self-release-please.yaml`, triggering on push
to `main`.
2. **No GitHub Releases.** `v0.1.0`–`v0.3.0` existed only as lightweight
git tags created by hand. Release-please reads the Releases API to find
the last version, so it would have ignored those tags and restarted
versioning at `1.0.0`. I backfilled releases for all three tags, with
`v0.3.0` marked latest, so the next run proposes `v0.4.0`.

## Self-repository syntax

The call uses `$/` rather than `./`:

```yaml
uses: $/.github/workflows/release-please.yaml
```

[GitHub shipped this in July
2026](https://github.blog/changelog/2026-07-30-reference-same-repository-actions-with-self-repository-syntax/).
It resolves to the exact running commit with no checkout, and unlike
`./` it counts as pinning for policy enforcement — which matters for a
repo whose whole purpose is publishing pinned workflows. zizmor's
`self-repository` audit recommends it. The alternative, pinning to
`masterpointio/actions@<sha>`, would need a bump on every single
release.

Tradeoff worth flagging: actionlint 1.7.12 predates the syntax and
rejects it, hence the scoped `trunk-ignore`. Requires runner 2.336.0+,
which GitHub-hosted runners satisfy. If the first run fails, swapping
`$/` for `./` is a one-line fallback.

## Follow-up

This repo also runs no CI on its own PRs — `lint.yaml` is likewise
`workflow_call`-only and there's no `.trunk` config. Separate PR, so a
first-time trunk run surfacing pre-existing findings doesn't block this
release fix.

## Testing

`actionlint`, `zizmor --persona=pedantic`, `yamllint`, and `prettier`
pass locally (borrowing a trunk config, since this repo has none).

Made with [Cursor](https://cursor.com)

Co-authored-by: Cursor <cursoragent@cursor.com>
gberenice pushed a commit that referenced this pull request Sep 21, 2026
🤖 I have created a release *beep* *boop*
---


##
[0.4.0](v0.3.0...v0.4.0)
(2026-09-21)


### Features

* discover and test every module in tf-test workflow
([#4](#4))
([5ca743a](5ca743a))


### Bug Fixes

* run release-please on this repo
([#5](#5))
([fc531db](fc531db))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: masterpointbot[bot] <177651640+masterpointbot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants