diff --git a/scripts/deploy.sh b/scripts/deploy.sh index 06b69bb..d422f69 100755 --- a/scripts/deploy.sh +++ b/scripts/deploy.sh @@ -26,6 +26,14 @@ cd "$ROOT" : "${AWS_PROFILE:?set AWS_PROFILE; default credentials are almost never the right account}" +# The variable being set says nothing about the session behind it. Ask STS +# now, so an expired login fails here instead of after the image build, when +# the push is the first thing to touch AWS. +if ! aws sts get-caller-identity --query Account --output text >/dev/null; then + echo "deploy: no working AWS session for profile $AWS_PROFILE; log in again" >&2 + exit 1 +fi + command -v jq >/dev/null || { echo "deploy: jq is not installed; it writes releases.auto.tfvars.json" >&2 exit 1 diff --git a/tests/shell/test-deploy.sh b/tests/shell/test-deploy.sh index fc2b0a9..7f0193d 100755 --- a/tests/shell/test-deploy.sh +++ b/tests/shell/test-deploy.sh @@ -18,6 +18,19 @@ trap 'rm -rf "$TMP"' EXIT pass=0; fail=0 check() { if "${@:2}"; then echo "ok $1"; pass=$((pass+1)); else echo "FAIL $1"; fail=$((fail+1)); fi; } +# deploy.sh asks STS whether the session behind AWS_PROFILE works, and these +# tests have no AWS. A stub answers for it, and STUB_STS_FAIL makes the stub +# refuse - which is also how that guard gets tested. Survives setup(), which +# only rebuilds the fake repos. +mkdir -p "$TMP/bin" +cat > "$TMP/bin/aws" <<'STUB' +#!/usr/bin/env bash +[ -z "${STUB_STS_FAIL:-}" ] || exit 255 +echo 123456789012 +STUB +chmod +x "$TMP/bin/aws" +export PATH="$TMP/bin:$PATH" + # A fake arena beside a fake infra, which is the layout deploy.sh assumes. # Rebuilt for every case so one case cannot leave state for the next. setup() { @@ -79,6 +92,10 @@ setup ( cd "$TMP/arena" && env -u AWS_PROFILE INFRA_DIR="$TMP/infra" ./scripts/deploy.sh ) >/dev/null 2>&1 check "refuses to run without AWS_PROFILE" test $? -ne 0 +setup +deploy STUB_STS_FAIL=1 +check "refuses when STS says the session is dead" test $? -ne 0 + setup ( cd "$TMP/arena" && env AWS_PROFILE=test INFRA_DIR="$TMP/nope" ./scripts/deploy.sh ) >/dev/null 2>&1 check "refuses when the infra checkout is not there" test $? -ne 0