fix(lefthook): validate opentofu from a clean copy so the encrypted local state is not read #476
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!476
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/lefthook-tofu-validate"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
The pre-push
opentofu validatejob added in #457 rantofu initinsideopentofu/, where the encrypted local state lives. Without the passphrase in the environment, init refuses to read it and the push is blocked, while the same job in CI (clean checkout, no state) passes. The job now copies the.tofufiles and the lock file into a temp directory and validates there, which is exactly what CI does.