From 70d9c770e28712ac2989134197c6df661c50fe1f Mon Sep 17 00:00:00 2001 From: Zack Date: Fri, 26 Jun 2026 16:29:09 +0100 Subject: [PATCH] ci: run customer zitadel staging deploy between dev and prod --- .github/workflows/terragrunt.yml | 42 ++++++++++++++++---------------- 1 file changed, 21 insertions(+), 21 deletions(-) diff --git a/.github/workflows/terragrunt.yml b/.github/workflows/terragrunt.yml index 63be25be..2a81eb3e 100644 --- a/.github/workflows/terragrunt.yml +++ b/.github/workflows/terragrunt.yml @@ -107,16 +107,6 @@ jobs: ENVIRONMENT: dev run: mise run tf:plan 2>&1 | tee "$RUNNER_TEMP/plan-dev.txt" - - name: Plan Prod - working-directory: ${{ env.working_dir }}/modules/scoped - env: - OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }} - OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }} - ENVIRONMENT: prod - run: | - mise run tf:init - mise run tf:plan 2>&1 | tee "$RUNNER_TEMP/plan-prod.txt" - # Staging only runs the customer ZITADEL module, not the whole scoped # suite — hence the deeper working-directory rather than ENVIRONMENT alone. - name: Plan Staging (zitadel customer) @@ -129,6 +119,16 @@ jobs: mise run tf:init mise run tf:plan 2>&1 | tee "$RUNNER_TEMP/plan-staging.txt" + - name: Plan Prod + working-directory: ${{ env.working_dir }}/modules/scoped + env: + OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }} + OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }} + ENVIRONMENT: prod + run: | + mise run tf:init + mise run tf:plan 2>&1 | tee "$RUNNER_TEMP/plan-prod.txt" + - name: Comment PR if: always() && github.event_name == 'pull_request' env: @@ -140,8 +140,8 @@ jobs: echo "" bash "$GITHUB_WORKSPACE/.github/scripts/parse-plan.sh" "$RUNNER_TEMP/plan-shared.txt" "Shared" bash "$GITHUB_WORKSPACE/.github/scripts/parse-plan.sh" "$RUNNER_TEMP/plan-dev.txt" "Scoped (dev)" - bash "$GITHUB_WORKSPACE/.github/scripts/parse-plan.sh" "$RUNNER_TEMP/plan-prod.txt" "Scoped (prod)" bash "$GITHUB_WORKSPACE/.github/scripts/parse-plan.sh" "$RUNNER_TEMP/plan-staging.txt" "Scoped (staging — zitadel customer)" + bash "$GITHUB_WORKSPACE/.github/scripts/parse-plan.sh" "$RUNNER_TEMP/plan-prod.txt" "Scoped (prod)" } > "$RUNNER_TEMP/plan-comment.md" char_count=$(wc -c < "$RUNNER_TEMP/plan-comment.md") @@ -209,16 +209,6 @@ jobs: ENVIRONMENT: dev run: mise run tf:apply - - name: Deploy Prod - working-directory: ${{ env.working_dir }}/modules/scoped - env: - OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }} - OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }} - ENVIRONMENT: prod - run: | - mise run tf:init - mise run tf:apply - # Staging only runs the customer ZITADEL module, not the whole scoped # suite — hence the deeper working-directory rather than ENVIRONMENT alone. - name: Deploy Staging (zitadel customer) @@ -230,3 +220,13 @@ jobs: run: | mise run tf:init mise run tf:apply + + - name: Deploy Prod + working-directory: ${{ env.working_dir }}/modules/scoped + env: + OP_CONNECT_HOST: ${{ secrets.OP_CONNECT_HOST }} + OP_CONNECT_TOKEN: ${{ secrets.OP_CONNECT_TOKEN_PROD }} + ENVIRONMENT: prod + run: | + mise run tf:init + mise run tf:apply