Skip to content

chore(deps): update actions/checkout action to v4.4.0 #417

chore(deps): update actions/checkout action to v4.4.0

chore(deps): update actions/checkout action to v4.4.0 #417

name: "Terragrunt plan central"
on:
workflow_dispatch:
pull_request:
paths:
- ".github/workflows/terragrunt-plan-central.yml"
- "satellite_accounts"
- "terragrunt/aws/central_account/**"
- "terragrunt/env/central/**"
- "terragrunt/env/common/**"
- "terragrunt/env/terragrunt.hcl"
env:
AWS_REGION: ca-central-1
CONFTEST_VERSION: 0.27.0
TERRAFORM_VERSION: 1.1.4
TERRAGRUNT_VERSION: 0.36.0
TF_INPUT: false
TF_VAR_cbs_principal_role_arn: ${{ secrets.CBS_PRINCIPAL_ROLE_ARN }}
TF_VAR_cbs_destination_event_bus_arn: ${{ secrets.CBS_DESTINATION_EVENT_BUS_ARN}}
TF_VAR_slack_webhook_url: ${{ secrets.SLACK_WEBHOOK_CBS }}
permissions:
id-token: write
contents: read
pull-requests: write
actions: write
checks: write
statuses: write
jobs:
terragrunt-plan:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Setup terraform tools
uses: cds-snc/terraform-tools-setup@36df0d7572a15921998170395475093c183d720a # v1.3.0
- uses: cds-snc/paths-filter@b316143212d841aed668b7b29240c719d603a9b9 # v2.10.4
id: filter
with:
filters: |
central_account:
- 'terragrunt/aws/central_account/**'
- 'terragrunt/env/central/central_account/**'
common:
- '.github/workflows/terragrunt-plan-central.yml'
- 'satellite_accounts'
- 'terragrunt/env/common/**'
- 'terragrunt/env/terragrunt.hcl'
- name: configure aws credentials using OIDC
uses: aws-actions/configure-aws-credentials@ffc08eae7350b1061d7de219e2135c75561fb680 # master
with:
role-to-assume: arn:aws:iam::871282759583:role/ConfigTerraformAdministratorRole
role-session-name: CBSGitHubActions
aws-region: "ca-central-1"
- name: Terragrunt plan central account
if: ${{ steps.filter.outputs.central_account == 'true' || steps.filter.outputs.common == 'true' }}
uses: cds-snc/terraform-plan@39b0058bcf977fbd8b067b84d5a9f6165e356c32 # v3.7.0
with:
directory: "terragrunt/env/central/central_account"
comment-delete: "true"
comment-title: "Central account"
github-token: "${{ secrets.GITHUB_TOKEN }}"
terragrunt: "true"