Skip to content

feat: Native CI Integration for Terraform - #2147

Merged
Igor Rodionov (goruha) merged 63 commits into
goruha/native-ci-terraform-planfrom
goruha/native-ci-terraform-plan-step-2-5
Mar 6, 2026
Merged

Igor Rodionov (goruha) merged 63 commits into
goruha/native-ci-terraform-planfrom
goruha/native-ci-terraform-plan-step-2-5

Conversation

@goruha

@goruha Igor Rodionov (goruha) commented Mar 6, 2026 •

Copy link
Copy Markdown
Member

Summary

Adds native CI integration to Atmos, enabling the same atmos terraform plan/apply commands to work identically locally and in CI—no wrapper scripts, no extra GitHub Actions, no hidden complexity.

  • CI Plugin Architecture: Extensible plugin/provider system (pkg/ci/) with terraform plugin and GitHub/generic providers
  • Automatic Plan Summaries: Rich markdown job summaries and CI output variables generated automatically when --ci is set
  • Planfile Storage: Multi-backend artifact storage (GitHub Artifacts, S3, local) with atmos terraform planfile CLI commands for upload/download/list/show/delete
  • CI Status Checks: GitHub check runs for plan/apply with in-progress and completion status
  • Plan Verification (FR-6): --verify-plan in CI mode downloads stored planfile with stored. prefix, generates fresh plan at canonical path, compares via plan-diff, and only proceeds with apply if they match
  • CI Status Command: atmos ci status command for querying CI pipeline status
  • Terraform Output Export: Automatic export of terraform outputs as CI variables after successful apply

Key Architecture

Package Purpose
pkg/ci/ Core CI executor, plugin registry, provider registry
pkg/ci/artifact/ Multi-backend artifact storage (GitHub, S3, local) with bundled tar support
pkg/ci/plugins/terraform/ Terraform CI plugin: plan summaries, planfile upload/download, check runs, output parsing
pkg/ci/providers/github/ GitHub Actions provider: checks API, job summaries, output variables
pkg/ci/providers/generic/ Generic CI provider for non-GitHub environments
pkg/ci/templates/ Template loader for CI summary rendering
cmd/ci/ `atmos ci status` command
cmd/terraform/planfile/ `atmos terraform planfile` subcommands

Flow

```
atmos terraform plan vpc -s prod --ci
→ before.terraform.plan: create check run (in_progress)
→ terraform plan (standard execution)
→ after.terraform.plan: parse output → render summary → upload planfile → update check run

atmos terraform apply vpc -s prod --ci --verify-plan
→ before.terraform.apply: download planfile to stored.plan.tfplan
→ verify: generate fresh plan → compare stored vs fresh → fail if different
→ terraform apply (from verified fresh plan)
→ after.terraform.apply: render summary → export outputs
```

Test plan

  • `go build ./...` passes
  • Unit tests for all new packages with mocked dependencies
  • Integration tests for CI plan/apply flow (`tests/terraform_plan_ci_test.go`)
  • Golden snapshot tests for plan/apply summaries
  • Planfile write/verification tests
  • Manual: `atmos terraform plan vpc -s prod --ci` in GitHub Actions
  • Manual: `atmos terraform apply vpc -s prod --ci --verify-plan`

References

  • PRD: `docs/prd/native-ci/overview.md`
  • Blog: `website/blog/2025-12-17-native-ci-integration.mdx`
  • Docs: `website/docs/cli/configuration/ci.mdx`

🤖 Generated with Claude Code

@github-actions

github-actions Bot commented Mar 6, 2026

Copy link
Copy Markdown

Warning

This PR is blocked from merging because a required semver label is missing.

major, minor, patch, no-release

You'll need to add one before this PR can be merged.

@goruha
Igor Rodionov (goruha) changed the base branch from main to goruha/native-ci-terraform-plan March 6, 2026 18:33
@goruha
Igor Rodionov (goruha) requested review from a team as code owners March 6, 2026 18:33
@github-actions

github-actions Bot commented Mar 6, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@mergify

mergify Bot commented Mar 6, 2026

Copy link
Copy Markdown
Contributor

Warning

This PR exceeds the recommended limit of 10,000 lines.

Large PRs are difficult to review and may be rejected due to their size.

Please verify that this PR does not address multiple issues.
Consider refactoring it into smaller, more focused PRs to facilitate a smoother review process.

@goruha
Igor Rodionov (goruha) merged commit a724e72 into goruha/native-ci-terraform-plan Mar 6, 2026
16 of 20 checks passed
@goruha
Igor Rodionov (goruha) deleted the goruha/native-ci-terraform-plan-step-2-5 branch March 6, 2026 18:34
@mergify mergify Bot added the stacked Stacked label Mar 6, 2026
@goruha Igor Rodionov (goruha) changed the title FR-6: CI-integrated stored vs fresh plan verification feat: Native CI Integration for Terraform Mar 6, 2026
@github-actions

Copy link
Copy Markdown

These changes were released in v1.210.0-test.0.

Igor Rodionov (goruha) added a commit that referenced this pull request Mar 16, 2026
…cle (#2079)

* feat: Add CI Summary Templates and --ci flag for automated pipelines

Implement comprehensive CI integration with rich tfcmt-style templates for terraform plan/apply outputs. Auto-generates job summaries, outputs, and artifact management.

- Add CIProvider interface for extensible CI component support
- Implement terraform CI provider with JSON-based output parsing
- Create embedded default templates (plan.md, apply.md) with resource counts, badges, and collapsible sections
- Add template loader with atmos.yaml override support (base_path, per-component templates)
- Add generic CI provider for local testing (--ci flag without platform detection)
- Implement unified CI executor with hook bindings and declarative actions
- Add golden file tests for template regression testing
- Add --ci flag to plan/apply commands (respects CI env var precedence)
- Wire CI hooks through terraform PostRunE for automatic execution

Template features match existing GitHub Actions with tfcmt formatting:
- Plan summaries with resource change badges (CREATE, CHANGE, REPLACE, DESTROY)
- Caution warning when resources will be deleted
- Terraform output variables table after apply
- Error/warning extraction from command output
- Markdown rendering with collapsible sections

CI integration is controlled by:
1. ci.enabled in atmos.yaml (enables/disables integration)
2. CI environment detection (GitHub Actions auto-detected)
3. --ci flag on plan/apply (forces CI mode for testing)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>

* fix: Add perf.Track and linting fixes for CI package

- Add defer perf.Track() to all public functions in CI package
- Fix import ordering (go-fumpt)
- Fix octal literal formatting (0644 → 0o644)
- Update golangci.yml to exclude pkg/ci/github/ from depguard
- Update lintroller to exclude pkg/ci/ from some checks
- Fix test file permission literals

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Add blog post announcing native CI integration

Announces the new native CI integration feature with:
- Simple GitHub Actions workflow examples
- Explanation of auto-detection and --ci flag
- Matrix strategy for multiple components
- Local testing instructions
- Configuration options

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Add missing planfile packages and fix broken blog link

The planfile command and pkg/ci/planfile packages were not committed
because .gitignore had a rule `**/planfile` which ignored any directory
named "planfile". Changed the rule to only ignore files matching
`*.planfile` pattern (already covered by existing rules).

Also:
- Fixed broken link in CI integration blog post that referenced /ci
- Added pkg/ci/planfile/s3/ to golangci exclusions for AWS SDK imports
- Fixed lint issues in internal/exec/describe_affected.go

Note: The newly tracked files have pre-existing lint issues that will
need to be addressed in a follow-up commit.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Remove duplicate defaultFilePermissions constant

The constant was already defined in docs_generate.go in the same package.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address all lint issues in CI integration code

Refactored CI integration code to resolve all lint issues without
using nolint directives:

- Extract helper functions to reduce cyclomatic/cognitive complexity
- Use pointer parameters for large structs (hugeParam fixes)
- Extract constants for magic numbers
- Refactor nested if blocks into early returns
- Split long functions into focused helpers

Files refactored:
- cmd/ci/status.go: Split getRepoContext into helper functions
- cmd/terraform/planfile/*.go: Extract format/download helpers
- pkg/ci/executor.go: Extract platform detection and binding logic
- pkg/ci/terraform/parser.go: Extract resource processing functions
- pkg/ci/planfile/github/store.go: Extract repo info and zip handling
- pkg/ci/templates/loader.go: Extract template loading by source

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* test: Update golden snapshots for CI integration

Regenerated golden snapshots to reflect new CI integration features:
- New `ci` command in atmos --help output
- New `planfile` subcommand under `terraform`
- New `--ci` flag for terraform plan/apply commands
- New CI configuration fields in describe config output

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Make TestLoaderResolvePath cross-platform compatible

Use filepath.FromSlash() for path literals in test expectations to
ensure the test passes on both Unix and Windows, where path separators
differ.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Update CI PRDs with implementation status

- native-ci-integration.md: Added Implementation Status section showing
  Phase 1 complete, Phase 2 ~70%, and Phases 3-6 pending. Updated
  package structure and Files to Create table with status indicators.
  Documented additional components implemented beyond original PRD.

- ci-summary-templates.md: Marked as complete with all files implemented.
  Added missing test files to the implementation table.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Clarify CI mode activation in blog post

Address review comment: clarify that ci.enabled: true in atmos.yaml
is respected as a way to enable CI mode. Added numbered list of
activation conditions and clarified precedence order.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration

This commit addresses multiple CodeRabbit review comments:

- cmd/terraform/planfile/download.go: Fix double %w error wrapping using
  errors.Join, fix Windows path handling using filepath.Base()
- cmd/terraform/planfile/upload.go: Fix unreachable GitHub Actions detection
  by reordering store type logic
- pkg/ci/github/checks.go: Add documentation for completed status mapping,
  remove unused mapGitHubConclusionToCheckRunState function
- pkg/ci/planfile/github/store.go: Add HTTP timeout (30s) for artifact
  downloads, fix error wrapping with errors.Join
- pkg/ci/planfile/local/store.go: Fix file filter to only skip .metadata.json
  files
- pkg/ci/planfile/s3/store.go: Simplify error check functions by removing
  unused second parameter
- pkg/ci/terraform/provider.go: Add nil check for result parameter in
  GetOutputVariables
- tools/lintroller/rule_perf_track.go: Add pkg/template exclusion with proper
  documentation

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address additional CodeRabbit review comments on CI integration

This commit addresses the second round of CodeRabbit review comments:

Comment #1 - Global flags in planfile commands:
- Add global flag parsing (--base-path, --config, --config-path, --profile)
  to delete.go, download.go, and upload.go using flags.ParseGlobalFlags()
- Refactored upload.go to extract helper functions and reduce function length

Comment #3 - GenerateKey placeholder validation:
- Add validation for required fields (Stack, Component, SHA) when used in pattern
- Return ErrPlanfileKeyInvalid error instead of leaving placeholders unreplaced
- Update interface_test.go with new test cases for validation behavior

Comments #4-5 - Golden file anchor mismatches:
- Update templates to use user-content- prefix on anchor IDs for proper
  markdown link fragment resolution
- Regenerate all golden files to match new template output

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* test: Add comprehensive CI integration test coverage

Add test files for CI integration packages to improve code coverage:

- pkg/ci/planfile/github/store_test.go: GitHub Artifacts store tests
- pkg/ci/planfile/s3/store_test.go: S3 store helper function tests
- pkg/ci/github/status_test.go: GitHub status fetching tests
- pkg/ci/github/checks_test.go: Check run creation/update tests
- cmd/ci/status_test.go: CI status command helper tests
- pkg/ci/output_test.go: Output writer tests
- cmd/terraform/planfile/upload_test.go: Upload command helper tests
- cmd/terraform/planfile/list_test.go: List formatting tests
- Expanded pkg/ci/executor_test.go with data structure tests
- Expanded pkg/ci/planfile/local/store_test.go with edge cases

Also removes accidentally committed lintroller binary and adds it to
.gitignore.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: Restructure CI config schema for provider-agnostic naming

Reorganize CI configuration from confusing nested structure to a cleaner,
provider-agnostic structure with four top-level capabilities:

- output: key=value pairs for downstream jobs (GitHub: $GITHUB_OUTPUT)
- summary: markdown job summary (GitHub: $GITHUB_STEP_SUMMARY)
- checks: commit status checks (GitHub: Check Runs API)
- comments: PR/MR comments (GitHub: PR comments, GitLab: MR notes)

Key changes:
- Rename status_checks -> checks
- Rename pr_comment -> comments
- Move variables under output where it belongs
- Remove outputs wrapper (was conflating concepts)
- Add template field to summary and comments configs

This structure supports GitHub Actions, GitLab CI, and other CI providers
with consistent, intuitive naming.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* feat: Wire up CI config settings to executor implementation

- Add isActionEnabled() to check if CI actions are enabled based on config
- Summary and Output enabled by default, Checks disabled by default
- Upload/Download always enabled (controlled by planfile config)
- Add filterVariables() to filter output variables by CI.Output.Variables
- Update executeSummaryAction() to support custom template from config
- Add comprehensive tests for config-aware behavior

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration

- Use ErrNotImplemented for GitHub Artifacts upload limitation
- Fix broken internal link fragment in plan_no_changes.md template
- Remove non-deterministic TestGetDefaultProvider test
- Remove tautological TestTableHeaderWidth and TestPlanfileInfoSorting tests
- Use errors.Is() for specific error sentinel verification in upload_test.go
- Handle JSON decode errors in checks_test.go mock handlers
- Check url.Parse errors in checks_test.go
- Fix config key names in PRD docs (ci.checks.enabled, ci.comments.enabled)
- Add Screengrab component to ci/status.mdx per documentation standards

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address error handling patterns in CI and config code

Changes:
- Use consistent fmt.Errorf("%w: ...") pattern in planfile store instead
  of errors.Join() for consistency with other methods
- Make error messages unique to avoid linter warning about duplicate
  string literals
- Fix type switch on error to use errors.As() in config loading
- Add nolint comment for ATMOS_CLI_CONFIG_PATH os.Getenv (bootstrap config)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Move ATMOS_PROFILE/ATMOS_IDENTITY env vars to job level

Move environment variables from step level to job level in workflow
examples for better practice. This ensures all steps in the job have
access to the environment variables without repetition.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Restructure PRD and blog with reproducibility narrative

Lead with WHY before WHAT: complex bash scripts in CI workflows signal
hidden complexity from tools not designed for CI. The reproducibility
principle—same command, same behavior everywhere—is now the core
narrative for native CI integration.

PRD changes:
- Add Executive Summary with key insight
- Expand Problem Statement with Hidden Complexity Problem
- Add The Reproducibility Principle section with before/after examples
- Rename "What You Get" to "What This Enables" (after context)
- Remove duplicate Problem Statement section

Blog post changes:
- Lead with reproducibility narrative
- Add "The Problem with CI Glue Code" section
- Add "The Reproducibility Principle" with concrete examples
- Add "What This Enables" to connect solution to problem

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* docs: Add formal functional requirements and fix matrix examples

Add Functional Requirements (FR-1 through FR-9):
- FR-1: CI Environment Detection
- FR-2: Job Summary Output
- FR-3: CI Output Variables
- FR-4: Status Checks
- FR-5: Planfile Storage
- FR-6: Plan Verification
- FR-7: Command Parity
- FR-8: Describe Affected Matrix Format
- FR-9: CI Status Command

Add Non-Functional Requirements (NFR-1 through NFR-4):
- NFR-1: Performance targets
- NFR-2: Reliability (graceful degradation)
- NFR-3: Security boundaries
- NFR-4: Extensibility

Fix matrix examples to use --output-file flag:
- Add --output-file="$GITHUB_OUTPUT" usage pattern
- Show complete workflow example with affected job
- Document key=value output format for $GITHUB_OUTPUT

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Remove pkg/template from perf-track exclusions

The pkg/template package performs template.Parse and recursive AST
tree traversal, which are non-trivial operations requiring perf
tracking per coding guidelines. Only trivial String() methods qualify
for exclusion.

Addresses CodeRabbit review comment.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration

- Parse global flags before loading config in ci status command
- Add static error sentinels for planfile operations
- Add validation to planfile registry Register function
- Wrap errors with static sentinels in local and S3 stores
- Fix MD028 violations in markdown templates with HTML comments

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* test: Update golden snapshots for CI schema and terraform flags

Update snapshots to reflect:
- CI config schema changes (outputs->output, status_checks->checks,
  pr_comment->comments, added summary section)
- New terraform apply flags (--auto-generate-backend-file,
  --init-run-reconfigure)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* test: Regenerate terraform plan help snapshot

Update snapshot for terraform plan --help to include new flags:
- --auto-generate-backend-file
- --init-run-reconfigure

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Use platform-specific absolute paths in TestLoaderResolvePath

On Windows, filepath.IsAbs() requires a drive letter (e.g., C:\) for a
path to be considered absolute. The test was using Unix-style paths
(/absolute/path) which become \absolute\path on Windows - not absolute.

This fix uses runtime.GOOS to select appropriate absolute paths for
each platform, ensuring the test works correctly on both Windows and
Unix systems.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on planfile commands

1. delete.go: Require --force flag for deletion (returns error instead
   of silently exiting), using static error ErrPlanfileDeleteRequireForce
2. list.go: Add global flag parsing (--base-path, --config, etc.)
3. show.go: Add global flag parsing (--base-path, --config, etc.)
4. check.go: Add Name field to UpdateCheckRunOptions (distinct from Title)
5. checks.go: Use opts.Name instead of opts.Title for GitHub API

Note: Comment #5 about template field access was investigated and found
to be a false positive. The templates correctly access fields from
TerraformTemplateContext which provides .Resources, .HasChanges() etc.
at the top level (not under .Result).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* refactor: Use StandardParser pattern and pkg/list for planfile commands

Refactor all 5 planfile commands (list, show, delete, download, upload) to:
1. Use StandardParser pattern for flag handling (instead of package-level variables)
2. Use pkg/list infrastructure for list output formatting (instead of custom formatters)

Benefits:
- Automatic environment variable support (ATMOS_PLANFILE_*)
- Proper precedence handling (CLI > ENV > config > defaults)
- Type-safe options structs
- Consistent output formatting with TTY detection
- Less code to maintain

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* chore: Add .claude/plans/ to .gitignore

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Rename shadowed fmt variable to outputFmt in list.go

The local variable `fmt` was shadowing the imported fmt package.
Renamed to `outputFmt` to avoid the shadowing issue.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration

- Use *bool pointer types for CI config Enabled fields to distinguish
  "not set" from "explicitly false" (fixes isActionEnabled defaults)
- Document Detect() non-deterministic map iteration order in registry.go
- Replace manual mock with mockgen-generated MockComponentCIProvider
- Add validation for empty Stack/ComponentFromArg in GetArtifactKey
- Add perf.Track() to RunCIHooks function per coding guidelines

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* chore: Add TODO comment for GetArtifactKey interface consideration

Address CodeRabbit feedback about aligning with planfile.GenerateKey
validation pattern. The current defensive approach with placeholders
is appropriate since the key is only used for debug logging, but noted
for future consideration if the interface is used for actual operations.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Remove unused PlanFile and Content fields from Hook struct

These fields were placeholders for deprecated CI hook commands
(ci.upload, ci.download, ci.summary). The modern approach uses
RunCIHooks which delegates to ci.Execute() with provider bindings.

Added comment explaining the deprecation and pointing to pkg/ci/.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration (part 2)

- GenericProvider: Return ErrCIOperationNotSupported error instead of
  (nil, nil) for GetStatus, CreateCheckRun, and UpdateCheckRun methods
  to prevent nil dereference panics at call sites
- s3/store.go: Wrap loadMetadata errors with ErrPlanfileMetadataFailed
  sentinel for consistent error handling
- loader_test.go: Handle fs.Sub error explicitly with panic for the
  (impossible) failure case since the directory is compile-time embedded

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Address CodeRabbit review comments on CI integration (part 3)

Security fixes:
- Add path traversal validation in local planfile store to prevent
  directory escape attacks via malicious keys

Bug fixes:
- Fix type assertion panic in hooks.go when "hooks" section is missing
- Replace custom errorAs with stdlib errors.As in S3 store

Code quality improvements:
- Replace custom replaceAll/indexOf functions with strings.ReplaceAll
- Fix comment/constant name mismatch in status.go
- Add error logging in GitHub provider init
- Simplify error wrapping in download.go using errUtils.Build()
- Use errUtils.Build() pattern in delete.go for consistency
- Refactor store detection into helper functions in upload.go

Implementation:
- Implement actual upload/download actions in executor.go instead of
  no-op placeholders. Actions now read/write planfiles to configured
  storage backends with proper metadata.

Documentation:
- Add thread-safety documentation for regex compilation in parser.go
- Add comment about file permissions in describe_affected.go
- Add planfile subcommand documentation (upload, download, list,
  delete, show)

Testing:
- Add path traversal prevention tests for local store
- Remove obsolete tests for deleted custom helper functions

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Wrap errors with static sentinels per CodeRabbit review

- Wrap file open errors in output.go with ErrCIOutputWriteFailed and
  ErrCISummaryWriteFailed sentinels
- Wrap JSON unmarshal errors in parser.go with ErrParseFile sentinel

This ensures consistent error checking using errors.Is() throughout
the codebase.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Wrap write errors with static sentinels per CodeRabbit review

- Wrap fmt.Fprintf error in WriteOutput with ErrCIOutputWriteFailed
- Wrap WriteString error in WriteSummary with ErrCISummaryWriteFailed

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* test: Regenerate golden snapshots for CI/terraform features

Update golden snapshot files to include new features added to this branch:
- ci command (CI/CD integration)
- planfile subcommand for terraform
- --ci flag for terraform plan
- planfiles configuration section

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* fix: Update ui.* calls to match new void-return API

Main branch merged #1980 which removed error returns from ui.* functions.
Updated cmd/ci/status.go and cmd/terraform/planfile/*.go to match the
new API that doesn't return values.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* [autofix.ci] apply automated fixes

* fix: Wrap CI status fetch failures with sentinel error

Address CodeRabbit feedback: Wrap provider.GetStatus errors with
ErrCIStatusFetchFailed sentinel so callers can reliably detect the
failure class, following coding guidelines for error handling.

Also fixes:
- gofumpt formatting in schema.go
- godot (comment periods) in log_utils.go

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

* [autofix.ci] apply automated fixes

* Added native ci fixtures

* Added test to clarify atmos terraform planfile list works

* Added terraform planfile cmd

* Move planfile name from options to flags

* Added planfile storage on terraform plan

* Regenerate snapshots for planfile subcommand in terraform help

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Regenerate secrets-masking snapshot for planfiles and ci config sections

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix readme and tests

* Refactor ci pkg - defnine providers and plugins

* Move generic provider to separate package

* [autofix.ci] apply automated fixes

* Separate provider and plugin interfaces

* Refactor code

* Refactor

* Refactor

* Refactoring

* Added before.terraform.plan hook

* Added before.terraform.plan

* Add CI failure test case and refactor generic provider UI output

Refactor UpdateCheckRun to use consistent UI method per status (success,
error, warning) for title and summary lines. Add mock-failure component
and acceptance test verifying check run failure reporting with --ci flag.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Added error checks

* Prepare cancel check test case

* Added outputs

* Fix outputs

* Fix tests

* Fix hooks

* Fix hooks

* Force local storage usage

* Force local storage usage

* Force local storage usage

* Added debug logs

* Fix golden snapshot

* Fix golden snapshot

* Install GHA

* Fix mock component

* Fix ci summary

* Fix tests

* Fix markdown

* Fix outputs parse

* [autofix.ci] apply automated fixes

* Fix parser

* Fix warning

* [autofix.ci] apply automated fixes

* Fix templating

* Fix templating

* Macos Tests takes more the 45 minutes

* Macos Tests takes more the 45 minutes

* Fix macos longs running tests

* Fix macos atmos vendor pull

* [autofix.ci] apply automated fixes

* Added native ci fixtures

* Added test to clarify atmos terraform planfile list works

* Added terraform planfile cmd

* Move planfile name from options to flags

* Added planfile storage on terraform plan

* Regenerate snapshots for planfile subcommand in terraform help

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Regenerate secrets-masking snapshot for planfiles and ci config sections

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix readme and tests

* Refactor ci pkg - defnine providers and plugins

* Move generic provider to separate package

* Separate provider and plugin interfaces

* [autofix.ci] apply automated fixes

* Refactor code

* Refactor

* Refactor

* Refactoring

* Added before.terraform.plan hook

* Added before.terraform.plan

* Add CI failure test case and refactor generic provider UI output

Refactor UpdateCheckRun to use consistent UI method per status (success,
error, warning) for title and summary lines. Add mock-failure component
and acceptance test verifying check run failure reporting with --ci flag.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Added error checks

* Prepare cancel check test case

* Added outputs

* Fix outputs

* Fix tests

* Fix hooks

* Fix hooks

* Force local storage usage

* Force local storage usage

* Force local storage usage

* Added debug logs

* Fix golden snapshot

* Install GHA

* Fix mock component

* Fix ci summary

* Fix tests

* Fix markdown

* Fix outputs parse

* Fix parser

* [autofix.ci] apply automated fixes

* Fix warning

* Fix templating

* [autofix.ci] apply automated fixes

* Fix templating

* Macos Tests takes more the 45 minutes

* Macos Tests takes more the 45 minutes

* Fix macos longs running tests

* Fix macos atmos vendor pull

* Fix git toolchain

* Added summary output

* [autofix.ci] apply automated fixes

* Improve terraform output parse

* Change release workflow to use feature release file

* Change release workflow to use auto-release script

* Fix plugin terraform outputs

* Fix terraform summary output

* Fix no changes template

* Fix test

* Fix ci summary

* Fix summary template

* Added test

* Added failure summary

* Parse errors

* Fix test

* Fix test

* Added github upload implementation

* [autofix.ci] apply automated fixes

* Added github upload implementation

* Fix github storage

* [autofix.ci] apply automated fixes

* Fix github storage

* Added md5

* Added artifacts storage

* Update PRD

* Update PRD

* FR-6: CI-integrated stored vs fresh plan verification (#2147)

* Added artifacts storage

* Update PRD

* Update PRD

* Accept artifact storage interface

* Updated PRD

* Implement phase 2

* Added planfile storage

* Update atmos in native-ci

* Update PRD

* Update native-ci-integration PRD

* Added deceompose PRD

* Decompose PRD

* Clarify questions

* Decompose clarification

* Decompose clarification

* Decompose clarification

* Decompose clarification

* Decompose clarification

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Update implemented features

* Refactor executor-plugin

* Refactor executor-plugin

* Refactor executor-plugin

* Update PRDs

* Update PRDs

* Move checkrun storage to github implementation

* planfile storage validation PRD

* Make local get sha from git

* Added PRD to fix planfile storage metadata

* Fix planfile storage medatada

* Store planfile with lock file

* Store planfile with lock file

* Store planfile with lock file

* Added planfile artifact store multiple files

* Added planfile artifact store multiple files

* Added planfile artifact store multiple files

* Added planfile artifact store multiple files

* Planfile and artifact store integration

* Define responsibility between planfile storage, artifact storage and backend storage

* Move github and s3 storage to artifact package

* Generaliza github storage

* Generaliza github storage

* Improve planfile cli

* Update status

* Added terraform apply ci

* Update prds

* Apply terraform outputs

* Update PRds with the status

* Apply CI plan verfication step 1

* planfile download fix prd

* Fix planfile download

* Fix planfile download

* Added apply verification plan

* [autofix.ci] apply automated fixes

* Fix CI test failures: update snapshots and stderr patterns

- Add --verify-plan flag to apply help golden snapshots
- Fix CI test stderr patterns: "CI action failed" → "CI hook" to match
  actual warning output ("CI hook handler failed", "CI check run creation failed")

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Update apply planfile storage prd

* Clarify PRds

* Added apply ci integration

* [autofix.ci] apply automated fixes

* Fix tests

* fix tests

* fix tests

* Set atmos.config ci.enabled top priority

* Update PRD

* Fix auth problem

* Fix outputs

* Fix output

* Added outputs parser

* [autofix.ci] apply automated fixes

* Fix github provider detection

* Fix apply output summary

* Enrich apply summary with resource lists and per-action badges

Rewrite apply.md template to match plan.md style: CloudPosse logo,
per-action-type badges (CREATE/CHANGE/DESTROY), CAUTION block for
destroys, and resource lists by action type in diff code blocks.

Parse resource names from apply progress lines (Creating/Modifying/
Destroying) to populate CreatedResources, UpdatedResources, and
DeletedResources. Downgrade check run token errors to Debug level.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Render badges inline on a single line in plan and apply summaries

Use right-trimming (-}}) on badge template blocks so multiple badges
(CREATE/CHANGE/REPLACE/DESTROY) render on the same line instead of
each appearing on a separate line.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Show plan diffs in apply summary instead of just result line

Rework cleanApplyOutput to strip pre-plan noise and apply progress
lines while keeping the plan resource diffs, apply result, and
outputs. This gives the apply summary the same detail as the plan
summary.

Add OpenTofu marker support for plan output stripping. Use
case-insensitive regex for progress lines since terraform outputs
"Still modifying..." with lowercase after Still.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Added apply warnings

* Skip planfile storages if prirorities are empty

* Fix github statuses update

* Make CI experementatl

* [autofix.ci] apply automated fixes

* Decrease timeout for jobs in test workflow

Reduced timeout for job and acceptance tests from 60 to 45 minutes.

* Fix tests with experimental message

* Update implementation status

* Fix tests

* Update documentation

* Update documentation

* Fix links

* Fix documentation

* Fix broken links

* Update documentation

* Address documentation comments

* Address documentation comments

* Fix tests

* Create PRD for storage rename

* Rename storage

* Update website documentation

* Resolve sha based on git for github

* Fix tests

* [autofix.ci] apply automated fixes

* Rollback generate command

* Rollback generate command

* PRD for commit statuses (#2206)

* PRD for commit statuses

* Added checks based on github commit status

* Fix tests

* [autofix.ci] apply automated fixes

* Fix tests

* Fix status check url

* Fix status check url

* Update website docs

* Update website docs

* Update website docs

---------

Co-authored-by: Erik Osterman <erik@cloudposse.com>
Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

stacked Stacked

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant