Skip to content

feat: harden AWS integration security and deployment evidence #17

feat: harden AWS integration security and deployment evidence

feat: harden AWS integration security and deployment evidence #17

name: AWS Serverless Validation
on:
pull_request:
paths:
- "serverless/**"
- "infra/aws/**"
- "scripts/aws_msk_e2e.py"
- "tests/test_aws_lambda_handlers.py"
- "tests/test_aws_security_boundaries.py"
- "tests/test_release_evidence_tools.py"
- ".github/workflows/aws-serverless.yml"
- ".github/workflows/aws-msk-integration.yml"
push:
branches: ["main"]
paths:
- "serverless/**"
- "infra/aws/**"
- "scripts/aws_msk_e2e.py"
- "tests/test_aws_lambda_handlers.py"
- "tests/test_aws_security_boundaries.py"
- "tests/test_release_evidence_tools.py"
- ".github/workflows/aws-serverless.yml"
- ".github/workflows/aws-msk-integration.yml"
permissions:
contents: read
jobs:
aws-unit-tests:
name: AWS credential-free unit tests
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: |
requirements.txt
requirements-dev.txt
- name: Install dependencies
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt -r requirements-dev.txt
- name: Run AWS and evidence unit tests
run: |
pytest -q \
tests/test_aws_lambda_handlers.py \
tests/test_aws_security_boundaries.py \
tests/test_release_evidence_tools.py
terraform-validate:
name: Terraform format and validate
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Set up Terraform
uses: hashicorp/setup-terraform@v3
with:
terraform_version: "1.9.8"
- name: Check Terraform formatting
run: terraform fmt -check -recursive infra/aws
- name: Initialize Terraform without a backend
working-directory: infra/aws
run: terraform init -backend=false
- name: Validate Terraform
working-directory: infra/aws
run: terraform validate