Skip to content

Lab04#6

Open
pepegx wants to merge 15 commits intomasterfrom
lab04
Open

Lab04#6
pepegx wants to merge 15 commits intomasterfrom
lab04

Conversation

@pepegx
Copy link
Owner

@pepegx pepegx commented Feb 19, 2026

Summary

This PR delivers Lab 4: Infrastructure as Code (Terraform & Pulumi).

It adds a full Terraform and Pulumi implementation for Yandex Cloud infrastructure, supporting documentation, and CI validation for Terraform.

Scope of Changes

Terraform

  • Added complete Terraform project in terraform/:
    • main.tf, variables.tf, outputs.tf, versions.tf
    • .tflint.hcl, .gitignore, terraform.tfvars.example
    • committed .terraform.lock.hcl for reproducibility
  • Implemented resources:
    • VPC network
    • subnet
    • security group
    • compute instance (NAT/public IP)
  • Added optional bonus flow for GitHub import:
    • isolated via enable_github_bonus (default false)
    • validation for required GitHub vars when bonus is enabled

Pulumi

  • Added complete Pulumi Python project in pulumi/:
    • Pulumi.yaml, __main__.py, requirements.txt, README.md, .gitignore
  • Implemented equivalent infrastructure:
    • VPC network
    • subnet
    • security group
    • compute instance (NAT/public IP)
  • Added stricter SSH rule handling:
    • allowed_ssh_cidr required when SG is enabled
    • disallows 0.0.0.0/0 for SSH CIDR

Documentation

  • Added full lab report: terraform/docs/LAB04.md
  • Report is fully in English
  • Includes:
    • architecture decisions
    • command evidence
    • Terraform vs Pulumi comparison
    • cleanup notes
    • bonus notes (CI + GitHub import)

CI/CD

  • Added Terraform workflow:
    • .github/workflows/terraform-ci.yml
  • Includes:
    • terraform fmt -check
    • terraform init -backend=false
    • terraform validate -no-color
    • tflint
  • Triggers only on terraform/** changes
  • Pinned Trivy action version (no @master)

Validation Performed

  • terraform validate -no-color
  • tflint --format compact
  • terraform plan (main scenario, SG enabled) ✅
  • pulumi preview (SG enabled) ✅
  • python3 -m py_compile pulumi/__main__.py

Known Limitation

Cloud provisioning in Yandex Cloud is blocked by folder IAM permissions (resource-manager.folder / SG ingress permissions).
Because of this, cloud VM SSH proof is blocked by external IAM constraints; local fallback evidence is documented in LAB04.md per lab alternative guidance.

pepega and others added 15 commits January 28, 2026 13:08
- Implement Flask-based DevOps Info Service (Python)
- Add GET / endpoint with service, system, runtime, and request info
- Add GET /health endpoint for monitoring
- Implement environment variable configuration (HOST, PORT, DEBUG)
- Add comprehensive documentation (README.md and LAB01.md)
- Include best practices: PEP 8, error handling, logging
- Add GitHub Community engagement section
- Implement bonus task: Go version of the service
- Add testing screenshots and evidence
- Pin dependencies in requirements.txt
- Configure .gitignore for Python and Go
- Add pytest unit tests (15 tests covering all endpoints)
- Add GitHub Actions workflow with matrix testing (Python 3.11, 3.12)
- Add ruff linter integration
- Add Docker build/push with CalVer versioning
- Add status badge to README
- Add LAB03.md documentation

Best practices:
- Dependency caching via setup-python
- Docker layer caching via Buildx
- Job dependencies (docker needs lint-test)
- Fail-fast matrix strategy
- Concurrency with cancel-in-progress
- Path filters for monorepo efficiency
- Docker build always runs (validates Dockerfile)
- Docker push only when DOCKERHUB secrets are configured
- Graceful handling when secrets not available
- Add .github/workflows/go-ci.yml for Go application
- Language-specific linting with golangci-lint
- Go testing with race detector and coverage
- Snyk security scanning for Go dependencies
- Docker build and push with CalVer versioning
- Path-based triggers for monorepo optimization
- Separate Docker image: pepegx/devops-info-service-go
- Parallel execution with Python CI workflow
…i-app support

Completes all main tasks (10pts) and bonus tasks (2.5pts):

MAIN TASKS (10pts):
- Unit Testing (3pts): pytest framework, 15 tests, 80% coverage
- GitHub Actions CI (4pts): python-ci.yml with matrix build, linting, testing, Docker push
- CI Best Practices (3pts): status badge, caching, Snyk security scanning

BONUS (2.5pts):
- Multi-App CI: go-ci.yml with path-based triggers
- Test Coverage: codecov integration with XML reporting

All requirements verified locally and ready for GitHub Actions execution.
- Fix codecov action file path (app_python/coverage.xml)
- Add CODECOV_TOKEN secret to codecov action
- Fix Snyk actions with proper file paths for both Python and Go
- Add Go CI status badge to app_go/README.md
- Fix codecov badge URL in app_python/README.md (remove token param)

All Lab03 requirements verified:
- 15 unit tests passing with 80% coverage
- Matrix builds for Python 3.11/3.12
- Snyk security scanning configured
- CalVer versioning implemented
- Path filters for monorepo
- Add main_test.go with 12 comprehensive unit tests
- Test all endpoints: /, /health, 404 handler
- Test helper functions: getEnv, getUptime, getSystemInfo
- Test custom mux wrapper with subtests
- Update README with unit testing documentation
- Update LAB03.md with test details

Coverage: 67.2% of statements
- Add pyproject.toml with 70% coverage threshold
- Configure pytest-cov fail-under for CI enforcement
- Add codecov upload for Go workflow
- Update LAB03.md with new coverage stats (98%)
- Simplify pytest command to use pyproject.toml config

Coverage improvements:
- Python: 98% coverage with 70% threshold
- Go: 67.2% coverage with codecov integration
- Refactor main.go: extract setupRouter() and printStartupBanner()
- Add TestSetupRouter to test router configuration
- Add TestPrintStartupBanner to test startup output
- Add TestDebugMode to test handlers with debug=true
- Coverage increased from 67.2% to 87.3% (above 70% threshold)
@codecov-commenter
Copy link

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

ℹ️ You can also turn on project coverage checks and project coverage reporting on Pull Request comment

Thanks for integrating Codecov - We've got you covered ☂️

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants