Skip to content

feat(gha): Revert "run the affected unit tests against OpenTofu (#439)" - #446

Merged
so0k merged 1 commit into
open-constructs:mainfrom
jsteinich:revert/opentofu-unit-axis
Sep 18, 2026
Merged

so0k merged 1 commit into
open-constructs:mainfrom
jsteinich:revert/opentofu-unit-axis

Conversation

@jsteinich

Copy link
Copy Markdown
Contributor

Related issue

Reverts #439, which is failing the OpenTofu unit job on every PR that touches a terraform-tagged project and blocking all CI since it merged.

Why it passed review and then broke main

#439's green check was vacuous. Its diff touched only .github/workflows/pr-unit.yml. The job it added runs nx affected -t test --exclude='*,!tag:unit-test:terraform', so on a workflow-only change nx affected resolved to no terraform-tagged projects and the OpenTofu job ran zero tests. The check went green having proved nothing.

That is the same shape as the release.yml matrix bug caught during review on the same PR: a workflow change whose effect cannot be observed from the PR that makes it.

Two independent problems, once it runs for real

1. Unsigned provider pins. OpenTofu rejects kreuzwerker/docker 2.16.0 (provider-generator/src/get/__tests__/generator/versions-file.test.ts:36) and 3.0.2 (provider-generator/src/__tests__/provider.test.ts:130):

Error while installing kreuzwerker/docker v2.16.0: the provider is not signed
with a valid signing key

Same class as #301 / #429 / #436 / #440. Missed because these carry the version inline in a test fixture rather than in a cdktf.json, so the earlier sweeps did not catch them. Signing starts at 3.7.0, not at the 3.x major — see #440.

2. Snapshots that embed a fully qualified provider name. provider-schema/src/__tests__/provider-schema.test.ts:

  "provider_versions": {
-   "registry.terraform.io/hashicorp/null": "3.1.0"
+   "registry.opentofu.org/hashicorp/null": "3.1.0"
  }

No single snapshot can satisfy both CLIs. This is not a pin bump — it needs the registry host normalised out of the snapshot, per-CLI snapshots, or those tests excluded from the tofu run. It is the same CLI-dependence #443 addresses for documentation links, showing up in schema snapshots.

Why revert rather than fix forward

Problem 1 is a two-line bump. Problem 2 needs a decision about how schema snapshots should behave across CLIs, and every PR is blocked while that is settled. Reverting restores CI now and lets the fixture and snapshot work land on its own merits.

What re-landing needs

  • Bump the two unsigned pins to a signed version (>= 3.7.0).
  • Decide how FQPN-bearing snapshots behave under a non-Terraform CLI.
  • Keep the axis red on its own PR until the fixtures are clean. A change to pr-unit.yml alone cannot demonstrate that the suites pass under OpenTofu; the PR that re-lands it should also touch a terraform-tagged project, or the job should be verified by running it directly.

🤖 Generated with Claude Code

…-constructs#439)"

This reverts commit 823682d.

The OpenTofu unit job fails on every PR that touches a terraform-tagged
project, blocking all CI since the merge.

It passed on its own PR vacuously. open-constructs#439's diff touched only
.github/workflows/pr-unit.yml, so `nx affected` resolved to no
terraform-tagged projects and the tofu job ran zero tests. The green check
proved nothing.

Two independent problems surface once it runs for real:

1. Unsigned provider pins OpenTofu rejects - kreuzwerker/docker 2.16.0 in
   provider-generator's versions-file.test.ts and 3.0.2 in its
   provider.test.ts. Same class as open-constructs#301/open-constructs#429/open-constructs#436/open-constructs#440, missed because those
   pins carry a version inline rather than in a cdktf.json.

2. Snapshots that embed a fully qualified provider name. provider-schema's
   provider-schema.test.ts snapshot contains
   "registry.terraform.io/hashicorp/null" under terraform and
   "registry.opentofu.org/hashicorp/null" under tofu. No single snapshot can
   satisfy both CLIs, so this is not a pin bump - it needs the host
   normalized out of the snapshot, per-CLI snapshots, or those tests excluded
   from the tofu run.

Reverting to unblock, rather than fixing forward, because (2) needs a
decision rather than a patch. Re-landing should keep the axis red on its own
PR until the fixtures are clean - a change to pr-unit.yml alone cannot
demonstrate that.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@jsteinich jsteinich changed the title Revert "feat(gha): run the affected unit tests against OpenTofu (#439)" feat(gha): Revert "run the affected unit tests against OpenTofu (#439)" Sep 18, 2026
@jsteinich
jsteinich marked this pull request as ready for review September 18, 2026 02:23
@jsteinich
jsteinich requested a review from a team as a code owner September 18, 2026 02:23
@so0k
so0k merged commit ae015ef into open-constructs:main Sep 18, 2026
261 of 262 checks passed
jsteinich added a commit to jsteinich/cdk-terrain that referenced this pull request Sep 19, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously -
its diff touched only pr-unit.yml, so `nx affected` resolved to no
terraform-tagged projects and the tofu job ran zero tests. It then failed on
every PR that touched one, and was reverted in open-constructs#446.

This branch touches provider-generator and provider-schema, so the tofu job
runs for real on its own PR.

Four things had to change, in two classes.

Unsigned providers OpenTofu rejects:

- versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts
  pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x
  major (open-constructs#440).
- provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform
  registry but not on OpenTofu's. It needs two same-named providers from
  different namespaces, so it moves to zahiar/bitbucket, which is on both.

Fully qualified names leaking the fetching CLI into expectations. The schema
JSON is keyed by FQPN, so the host records which binary fetched it rather
than anything about the code under test:

- provider-schema.test.ts snapshots the raw schema. Its sanitizer already
  stubs format_version, cli_name and cli_version for this exact reason;
  provider_schemas and provider_versions keys now get the same treatment.
  Keys only - a host inside provider documentation text is identical either
  way and stays as authored.
- versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`;
  it now compares the provider part.
- provider.test.ts snapshots a generated directory including versions.json;
  FQPN keys are normalized there too.

Verified against both CLIs rather than assumed: @cdktn/provider-generator
23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites /
58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6.

The generated docs links that also differed by CLI are fixed by open-constructs#443, which
this is stacked on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jsteinich added a commit to jsteinich/cdk-terrain that referenced this pull request Sep 23, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously -
its diff touched only pr-unit.yml, so `nx affected` resolved to no
terraform-tagged projects and the tofu job ran zero tests. It then failed on
every PR that touched one, and was reverted in open-constructs#446.

This branch touches provider-generator and provider-schema, so the tofu job
runs for real on its own PR.

Four things had to change, in two classes.

Unsigned providers OpenTofu rejects:

- versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts
  pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x
  major (open-constructs#440).
- provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform
  registry but not on OpenTofu's. It needs two same-named providers from
  different namespaces, so it moves to zahiar/bitbucket, which is on both.

Fully qualified names leaking the fetching CLI into expectations. The schema
JSON is keyed by FQPN, so the host records which binary fetched it rather
than anything about the code under test:

- provider-schema.test.ts snapshots the raw schema. Its sanitizer already
  stubs format_version, cli_name and cli_version for this exact reason;
  provider_schemas and provider_versions keys now get the same treatment.
  Keys only - a host inside provider documentation text is identical either
  way and stays as authored.
- versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`;
  it now compares the provider part.
- provider.test.ts snapshots a generated directory including versions.json;
  FQPN keys are normalized there too.

Verified against both CLIs rather than assumed: @cdktn/provider-generator
23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites /
58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6.

The generated docs links that also differed by CLI are fixed by open-constructs#443, which
this is stacked on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
jsteinich added a commit to jsteinich/cdk-terrain that referenced this pull request Sep 23, 2026
Re-lands open-constructs#439 with the fixtures actually fixed. That PR passed vacuously -
its diff touched only pr-unit.yml, so `nx affected` resolved to no
terraform-tagged projects and the tofu job ran zero tests. It then failed on
every PR that touched one, and was reverted in open-constructs#446.

This branch touches provider-generator and provider-schema, so the tofu job
runs for real on its own PR.

Four things had to change, in two classes.

Unsigned providers OpenTofu rejects:

- versions-file.test.ts pinned kreuzwerker/docker 2.16.0 and provider.test.ts
  pinned 3.0.2. Both move to 3.9.0; signing starts at 3.7.0, not at the 3.x
  major (open-constructs#440).
- provider.test.ts used andsafe-AG/bitbucket, which exists on the Terraform
  registry but not on OpenTofu's. It needs two same-named providers from
  different namespaces, so it moves to zahiar/bitbucket, which is on both.

Fully qualified names leaking the fetching CLI into expectations. The schema
JSON is keyed by FQPN, so the host records which binary fetched it rather
than anything about the code under test:

- provider-schema.test.ts snapshots the raw schema. Its sanitizer already
  stubs format_version, cli_name and cli_version for this exact reason;
  provider_schemas and provider_versions keys now get the same treatment.
  Keys only - a host inside provider documentation text is identical either
  way and stays as authored.
- versions-file.test.ts asserted keys equal to `registry.terraform.io/${fqn}`;
  it now compares the provider part.
- provider.test.ts snapshots a generated directory including versions.json;
  FQPN keys are normalized there too.

Verified against both CLIs rather than assumed: @cdktn/provider-generator
23 suites / 117 tests / 101 snapshots and @cdktn/provider-schema 6 suites /
58 tests / 10 snapshots pass under terraform and under OpenTofu 1.12.6.

The generated docs links that also differed by CLI are fixed by open-constructs#443, which
this is stacked on.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants