fix(lefthook): validate opentofu from a clean copy so the encrypted local state is not read #476

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/lefthook-tofu-validate in i main 2026-09-08 23:28:12 +00:00
Ägare

The pre-push opentofu validate job added in #457 ran tofu init inside opentofu/, where the encrypted local state lives. Without the passphrase in the environment, init refuses to read it and the push is blocked, while the same job in CI (clean checkout, no state) passes. The job now copies the .tofu files and the lock file into a temp directory and validates there, which is exactly what CI does.

The pre-push `opentofu validate` job added in #457 ran `tofu init` inside `opentofu/`, where the encrypted local state lives. Without the passphrase in the environment, init refuses to read it and the push is blocked, while the same job in CI (clean checkout, no state) passes. The job now copies the `.tofu` files and the lock file into a temp directory and validates there, which is exactly what CI does.
supernaut lade till 1 incheckning 2026-09-08 23:25:47 +00:00
supernaut sammanfogade incheckning 18f070c17c till main 2026-09-08 23:28:12 +00:00
supernaut tog bort grenen fix/lefthook-tofu-validate 2026-09-08 23:28:12 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!476
Ingen beskrivning angiven.