Skip to content
This repository has been archived by the owner on Oct 15, 2024. It is now read-only.

Commit

Permalink
Merge pull request #15 from kids-first/feature/cbl/deployment-config
Browse files Browse the repository at this point in the history
♻️ Refactor lambda code to deploy Container lambda
  • Loading branch information
devbyaccident authored Dec 12, 2022
2 parents bdbdaa1 + 11a24ad commit 2fda49f
Show file tree
Hide file tree
Showing 41 changed files with 1,037 additions and 218 deletions.
22 changes: 22 additions & 0 deletions .github/workflows/bc_check.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
---
name: Run Bridgecrew
on:
pull_request:
branches: [master]
workflow_dispatch:

jobs:
bridgecrew:
name: Check IaC rules
runs-on: ubuntu-latest
steps:
# Checks-out your repository under $GITHUB_WORKSPACE, so your job can access it
- name: Checkout codebase
uses: actions/checkout@v3

- name: Run Bridgecrew
id: Bridgecrew
uses: bridgecrewio/bridgecrew-action@master
with:
api-key: ${{ secrets.BRIDGECREW_API_KEY }}
directory: deployment/terraform
2 changes: 1 addition & 1 deletion .github/workflows/check_pull_request.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
cache: 'pip'
- name: Install Dependencies
run: |
pip install -r dev-requirements.txt -r requirements.txt
pip install -r src/requirements.txt -r requirements.txt
shell: bash
- name: Run Unit Tests
run: pytest tests/unit
Expand Down
28 changes: 28 additions & 0 deletions .github/workflows/linter.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
---
name: Lint Code Base
on:
pull_request:
branches: [master]
workflow_dispatch:

jobs:
build:
name: Lint New Commits
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v3
with:
fetch-depth: 0

- name: Lint Code Base
uses: github/super-linter@v4
env:
VALIDATE_ALL_CODEBASE: false
DEFAULT_BRANCH: master
VALIDATE_BASH: false
VALIDATE_JSCPD: false
VALIDATE_MARKDOWN: false
VALIDATE_PYTHON_ISORT: false
VALIDATE_TERRAFORM_TFLINT: false
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
23 changes: 23 additions & 0 deletions .github/workflows/terraform.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: Terraform Plan
on:
pull_request:
branches: [master]

jobs:

Terraform-Fmt:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v3
- uses: hashicorp/setup-terraform@v1.3.2
with:
terraform_version: 0.14.6

- name: Terraform fmt
id: fmt
run: terraform fmt -recursive

- uses: stefanzweifel/git-auto-commit-action@v4
with:
commit_message: 🎨 Apply terraform fmt
23 changes: 23 additions & 0 deletions .github/workflows/yor.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
name: IaC trace

on:
pull_request:
branches: [master]

# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:

jobs:
yor:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
name: Checkout repo
with:
fetch-depth: 0
ref: ${{ github.head_ref }}
- name: Run yor action and commit
uses: bridgecrewio/yor-action@main
with:
directory: deployment/terraform

174 changes: 169 additions & 5 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,170 @@
venv
.pytest_cache
.idea
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class

# C extensions
*.so

# Distribution / packaging
.Python
build/
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST

# PyInstaller
# Usually these files are written by a python script from a template
# before PyInstaller builds the exe, so as to inject date/other infos into it.
*.manifest
*.spec

# Installer logs
pip-log.txt
pip-delete-this-directory.txt

# Unit test / coverage reports
htmlcov/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
cover/

# Translations
*.mo
*.pot

# Django stuff:
*.log
local_settings.py
db.sqlite3
db.sqlite3-journal

# Flask stuff:
instance/
.webassets-cache

# Scrapy stuff:
.scrapy

# Sphinx documentation
docs/_build/

# PyBuilder
.pybuilder/
target/

# Jupyter Notebook
.ipynb_checkpoints

# IPython
profile_default/
ipython_config.py

# pyenv
# For a library or package, you might want to ignore these files since the code is
# intended to run in multiple environments; otherwise, check them in:
# .python-version

# pipenv
# According to pypa/pipenv#598, it is recommended to include Pipfile.lock in version control.
# However, in case of collaboration, if having platform-specific dependencies or dependencies
# having no cross-platform support, pipenv may install dependencies that don't work, or not
# install all needed dependencies.
#Pipfile.lock

# poetry
# Similar to Pipfile.lock, it is generally recommended to include poetry.lock in version control.
# This is especially recommended for binary packages to ensure reproducibility, and is more
# commonly ignored for libraries.
# https://python-poetry.org/docs/basic-usage/#commit-your-poetrylock-file-to-version-control
#poetry.lock

# pdm
# Similar to Pipfile.lock, it is generally recommended to include pdm.lock in version control.
#pdm.lock
# pdm stores project-wide configurations in .pdm.toml, but it is recommended to not include it
# in version control.
# https://pdm.fming.dev/#use-with-ide
.pdm.toml

# PEP 582; used by e.g. github.com/David-OConnor/pyflow and github.com/pdm-project/pdm
__pypackages__/

# Celery stuff
celerybeat-schedule
celerybeat.pid

# SageMath parsed files
*.sage.py

# Environments
.env
**/__pycache__
*.pyc
.venv
env/
venv/
ENV/
env.bak/
venv.bak/

# Spyder project settings
.spyderproject
.spyproject

# Rope project settings
.ropeproject

# mkdocs documentation
/site

# mypy
.mypy_cache/
.dmypy.json
dmypy.json

# Pyre type checker
.pyre/

# pytype static type analyzer
.pytype/

# Cython debug symbols
cython_debug/

# PyCharm
# JetBrains specific template is maintained in a separate JetBrains.gitignore that can
# be found at https://github.com/github/gitignore/blob/main/Global/JetBrains.gitignore
# and can be added to the global gitignore or merged into this file. For a more nuclear
# option (not recommended) you can uncomment the following to ignore the entire idea folder.
#.idea/

# Adding terraform for deployment config
.terraform/
*.zip
*.tfvars
*.tfplan
*.conf
deployment/python
deployment/terraform/lambda_layer/
**/.DS_Store
3 changes: 3 additions & 0 deletions .vscode/settings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"python.formatting.provider": "black"
}
10 changes: 5 additions & 5 deletions Dockerfile
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
FROM public.ecr.aws/lambda/python:3.8
FROM public.ecr.aws/lambda/python:3.9

COPY requirements.txt .
RUN pip3 install -r requirements.txt --target "${LAMBDA_TASK_ROOT}"
WORKDIR /code

COPY mappings.py service.py "${LAMBDA_TASK_ROOT}"/
COPY src/ ${LAMBDA_TASK_ROOT}
RUN pip3 install -r ${LAMBDA_TASK_ROOT}/requirements.txt --target "${LAMBDA_TASK_ROOT}" --no-cache-dir

CMD [ "service.handler" ]
CMD ["app.handler"]
10 changes: 0 additions & 10 deletions Dockerfile-dev

This file was deleted.

Loading

0 comments on commit 2fda49f

Please sign in to comment.