feat(gha): Revert "run the affected unit tests against OpenTofu (#439)" - #446
Merged
Merged
Conversation
…-constructs#439)" This reverts commit 823682d. The OpenTofu unit job fails on every PR that touches a terraform-tagged project, blocking all CI since the merge. It passed on its own PR vacuously. open-constructs#439's diff touched only .github/workflows/pr-unit.yml, so `nx affected` resolved to no terraform-tagged projects and the tofu job ran zero tests. The green check proved nothing. Two independent problems surface once it runs for real: 1. Unsigned provider pins OpenTofu rejects - kreuzwerker/docker 2.16.0 in provider-generator's versions-file.test.ts and 3.0.2 in its provider.test.ts. Same class as open-constructs#301/open-constructs#429/open-constructs#436/open-constructs#440, missed because those pins carry a version inline rather than in a cdktf.json. 2. Snapshots that embed a fully qualified provider name. provider-schema's provider-schema.test.ts snapshot contains "registry.terraform.io/hashicorp/null" under terraform and "registry.opentofu.org/hashicorp/null" under tofu. No single snapshot can satisfy both CLIs, so this is not a pin bump - it needs the host normalized out of the snapshot, per-CLI snapshots, or those tests excluded from the tofu run. Reverting to unblock, rather than fixing forward, because (2) needs a decision rather than a patch. Re-landing should keep the axis red on its own PR until the fixtures are clean - a change to pr-unit.yml alone cannot demonstrate that. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jsteinich
marked this pull request as ready for review
September 18, 2026 02:23
so0k
approved these changes
Sep 18, 2026
jsteinich
added a commit
to jsteinich/cdk-terrain
that referenced
this pull request
Sep 19, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously - its diff touched only pr-unit.yml, so `nx affected` resolved to no terraform-tagged projects and the tofu job ran zero tests. It then failed on every PR that touched one, and was reverted in open-constructs#446. This branch touches provider-generator and provider-schema, so the tofu job runs for real on its own PR. Four things had to change, in two classes. Unsigned providers OpenTofu rejects: - versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x major (open-constructs#440). - provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform registry but not on OpenTofu's. It needs two same-named providers from different namespaces, so it moves to zahiar/bitbucket, which is on both. Fully qualified names leaking the fetching CLI into expectations. The schema JSON is keyed by FQPN, so the host records which binary fetched it rather than anything about the code under test: - provider-schema.test.ts snapshots the raw schema. Its sanitizer already stubs format_version, cli_name and cli_version for this exact reason; provider_schemas and provider_versions keys now get the same treatment. Keys only - a host inside provider documentation text is identical either way and stays as authored. - versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`; it now compares the provider part. - provider.test.ts snapshots a generated directory including versions.json; FQPN keys are normalized there too. Verified against both CLIs rather than assumed: @cdktn/provider-generator 23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites / 58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6. The generated docs links that also differed by CLI are fixed by open-constructs#443, which this is stacked on. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jsteinich
added a commit
to jsteinich/cdk-terrain
that referenced
this pull request
Sep 23, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously - its diff touched only pr-unit.yml, so `nx affected` resolved to no terraform-tagged projects and the tofu job ran zero tests. It then failed on every PR that touched one, and was reverted in open-constructs#446. This branch touches provider-generator and provider-schema, so the tofu job runs for real on its own PR. Four things had to change, in two classes. Unsigned providers OpenTofu rejects: - versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x major (open-constructs#440). - provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform registry but not on OpenTofu's. It needs two same-named providers from different namespaces, so it moves to zahiar/bitbucket, which is on both. Fully qualified names leaking the fetching CLI into expectations. The schema JSON is keyed by FQPN, so the host records which binary fetched it rather than anything about the code under test: - provider-schema.test.ts snapshots the raw schema. Its sanitizer already stubs format_version, cli_name and cli_version for this exact reason; provider_schemas and provider_versions keys now get the same treatment. Keys only - a host inside provider documentation text is identical either way and stays as authored. - versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`; it now compares the provider part. - provider.test.ts snapshots a generated directory including versions.json; FQPN keys are normalized there too. Verified against both CLIs rather than assumed: @cdktn/provider-generator 23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites / 58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6. The generated docs links that also differed by CLI are fixed by open-constructs#443, which this is stacked on. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jsteinich
added a commit
to jsteinich/cdk-terrain
that referenced
this pull request
Sep 23, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously - its diff touched only pr-unit.yml, so `nx affected` resolved to no terraform-tagged projects and the tofu job ran zero tests. It then failed on every PR that touched one, and was reverted in open-constructs#446. This branch touches provider-generator and provider-schema, so the tofu job runs for real on its own PR. Four things had to change, in two classes. Unsigned providers OpenTofu rejects: - versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x major (open-constructs#440). - provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform registry but not on OpenTofu's. It needs two same-named providers from different namespaces, so it moves to zahiar/bitbucket, which is on both. Fully qualified names leaking the fetching CLI into expectations. The schema JSON is keyed by FQPN, so the host records which binary fetched it rather than anything about the code under test: - provider-schema.test.ts snapshots the raw schema. Its sanitizer already stubs format_version, cli_name and cli_version for this exact reason; provider_schemas and provider_versions keys now get the same treatment. Keys only - a host inside provider documentation text is identical either way and stays as authored. - versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`; it now compares the provider part. - provider.test.ts snapshots a generated directory including versions.json; FQPN keys are normalized there too. Verified against both CLIs rather than assumed: @cdktn/provider-generator 23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites / 58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6. The generated docs links that also differed by CLI are fixed by open-constructs#443, which this is stacked on. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issue
Reverts #439, which is failing the OpenTofu unit job on every PR that touches a terraform-tagged project and blocking all CI since it merged.
Why it passed review and then broke main
#439's green check was vacuous. Its diff touched only
.github/workflows/pr-unit.yml. The job it added runsnx affected -t test --exclude='*,!tag:unit-test:terraform', so on a workflow-only changenx affectedresolved to no terraform-tagged projects and the OpenTofu job ran zero tests. The check went green having proved nothing.That is the same shape as the
release.ymlmatrix bug caught during review on the same PR: a workflow change whose effect cannot be observed from the PR that makes it.Two independent problems, once it runs for real
1. Unsigned provider pins. OpenTofu rejects
kreuzwerker/docker2.16.0 (provider-generator/src/get/__tests__/generator/versions-file.test.ts:36) and 3.0.2 (provider-generator/src/__tests__/provider.test.ts:130):Same class as #301 / #429 / #436 / #440. Missed because these carry the version inline in a test fixture rather than in a
cdktf.json, so the earlier sweeps did not catch them. Signing starts at 3.7.0, not at the 3.x major — see #440.2. Snapshots that embed a fully qualified provider name.
provider-schema/src/__tests__/provider-schema.test.ts:"provider_versions": { - "registry.terraform.io/hashicorp/null": "3.1.0" + "registry.opentofu.org/hashicorp/null": "3.1.0" }No single snapshot can satisfy both CLIs. This is not a pin bump — it needs the registry host normalised out of the snapshot, per-CLI snapshots, or those tests excluded from the tofu run. It is the same CLI-dependence #443 addresses for documentation links, showing up in schema snapshots.
Why revert rather than fix forward
Problem 1 is a two-line bump. Problem 2 needs a decision about how schema snapshots should behave across CLIs, and every PR is blocked while that is settled. Reverting restores CI now and lets the fixture and snapshot work land on its own merits.
What re-landing needs
pr-unit.ymlalone cannot demonstrate that the suites pass under OpenTofu; the PR that re-lands it should also touch a terraform-tagged project, or the job should be verified by running it directly.🤖 Generated with Claude Code