Skip to content

feat(e2e): add supportability-matrix CI workflow and supporting fixes - #330

Merged
vaishakdinesh merged 6 commits into
mainfrom
supportability-matrix-ci
Oct 9, 2026
Merged

vaishakdinesh merged 6 commits into
mainfrom
supportability-matrix-ci

Conversation

@vaishakdinesh

Copy link
Copy Markdown
Member

Summary

Adds .github/workflows/supportability-matrix.yml, which tests tf-migrate's v4→v5 config migration against every provider version in the known supportability matrix (5.19.0, 5.19.1, 5.20.0, 5.21.1, 5.22.0, 5.23.0), triggered weekly and via workflow_dispatch (optionally targeting a single version). Legs run strictly sequentially against one shared, persistent v4 resource base, installing each target provider version fresh from the public Terraform Registry (no local provider build).

This does not replace or trigger on push to main yet — e2e-tests.yml stays in place for now. That migration, plus README/provider-migration-guide updates, will follow in a separate change.

Supporting fixes this workflow depends on

  • internal/e2e-runner/runner.go, version_suffix.go: fixes a bug where the harness's obsolete-state-cleanup step deleted state entries by type name alone, including ones with a moved {} counterpart — causing zero_trust_access_policy (and similarly-shaped resources) to be destroyed and recreated on every run instead of reusing existing state. Cleanup is now scoped to only entries without a moved {} block.
  • e2e/drift-exemptions/{argo,tiered_cache,zero_trust_access_policy,zero_trust_tunnel_cloudflared_route,zone_setting}.yaml: scope previously unscoped allow_resource_creation: true exemptions to their intended resource_types/resource_name_patterns. These were silently masking the state-cleanup bug above (and similar churn).
  • e2e/drift-exemptions/zero_trust_organization.yaml (new): scoped exemption for the v5.23.0 mfa_required_for_all_apps normalization one-time diff.
  • e2e/drift-exemptions/zero_trust_access_group.yaml (new): scoped exemption for one-time condition-explosion list-reordering drift on first apply.
  • integration/v4_to_v5/testdata/zero_trust_access_group/input/zero_trust_access_group_e2e.tf (new): e2e-safe variant omitting only the gsuite_list_email pattern, which requires a real Google Workspace (googleapps) identity provider not available in test environments. All other 34 patterns are confirmed working against the live API.
  • .gitignore: ignore version-isolated local directories (e2e/tf/v4-*/, e2e/migrated-v4_to_v5-*/, e2e/tmp-*/) used by --version-suffix runs.

Testing

  • go build ./... — clean
  • go test ./internal/... — all pass
  • make lint-testdata — pass
  • All 6 target versions manually live-tested end-to-end (v4 apply → migrate → v5 plan → v5 apply → stability plan) prior to this PR; full findings tracked separately (not included in this PR, to follow with README/migration-guide updates).

Adds .github/workflows/supportability-matrix.yml, which tests tf-migrate's
v4->v5 config migration against every provider version in the known
supportability matrix (5.19.0, 5.19.1, 5.20.0, 5.21.1, 5.22.0, 5.23.0),
triggered weekly and via workflow_dispatch (optionally targeting a single
version). Legs run sequentially against one shared, persistent v4 resource
base, installing each target provider version from the public registry.

Includes the fixes this workflow depends on to produce accurate results:

- internal/e2e-runner/runner.go, version_suffix.go: fix a bug where the
  harness's obsolete-state-cleanup step deleted state entries by type name
  alone, including ones with a moved {} counterpart - causing
  zero_trust_access_policy (and any similarly-shaped resource) to be
  destroyed and recreated on every run instead of correctly reusing existing
  state. Scoped the cleanup to only entries without a moved {} block.

- e2e/drift-exemptions/{argo,tiered_cache,zero_trust_access_policy,
  zero_trust_tunnel_cloudflared_route,zone_setting}.yaml: scope previously
  unscoped "allow_resource_creation: true" exemptions to their intended
  resource_types/resource_name_patterns. These were silently masking the
  state-cleanup bug above (and similar churn) across every resource type
  they matched.

- e2e/drift-exemptions/zero_trust_organization.yaml (new): scoped exemption
  for the v5.23.0 mfa_required_for_all_apps normalization one-time diff.

- e2e/drift-exemptions/zero_trust_access_group.yaml (new): scoped exemption
  for one-time condition-explosion list-reordering drift on first apply.

- integration/v4_to_v5/testdata/zero_trust_access_group/input/
  zero_trust_access_group_e2e.tf (new): e2e-safe variant omitting only the
  gsuite_list_email pattern, which requires a real Google Workspace
  (googleapps) identity provider that test environments may not have
  configured. All other 34 patterns in the full testdata are confirmed to
  work against the live API, including ones using fake identity_provider_id
  values for azure/okta selectors.

- .gitignore: ignore version-isolated local directories
  (e2e/tf/v4-*/, e2e/migrated-v4_to_v5-*/, e2e/tmp-*/) used by
  --version-suffix runs.
@vaishakdinesh
vaishakdinesh requested a review from a team as a code owner October 8, 2026 19:13
GitHub Actions rejects the matrix context in a job-level if: condition
("Unrecognized named-value: 'matrix'"), which caused the first CI run
on this branch to fail with zero jobs created before any test logic ran.
Moved the same condition to the step-level if on the actual test-execution
step, where the matrix context is valid. Non-matching legs now still
create a job (cheap checkout/setup steps run) but skip the real e2e run.
TEMPORARY commit — adds a push trigger scoped to this branch only, so the
workflow_dispatch-only workflow can get one real validation run before
merge (workflow_dispatch requires the workflow to already exist on the
default branch, which it doesn't yet). Will be reverted before merge.
@vaishakdinesh vaishakdinesh self-assigned this Oct 9, 2026
The push trigger scoped to this PR branch was only added to get one real
CI run before merge, since workflow_dispatch can't trigger a workflow that
doesn't yet exist on the default branch. It's served its purpose — the
workflow ran successfully end-to-end for all 6 matrix legs (run 37835491990)
after the matrix-context-in-job-if fix. Final triggers are workflow_dispatch
(optionally targeting a single version) and the weekly schedule only.
Both are superseded by supportability-matrix.yml, which covers every
version e2e-tests.yml tested (and five more) by installing from the
registry instead of building from source. e2e-tests-next.yml (manual-only,
builds the provider from its next branch tip) is removed too — accepting
the loss of next-branch regression testing for now.

Also fixes now-stale references to the deleted e2e-tests.yml:
- Go doc comments in cmd/e2e-runner/main.go and internal/e2e-runner/
  {init,runner,version_suffix}.go describing the shared/unsuffixed state
  key and directories no longer name a specific deleted workflow as the
  example consumer of that shared slot.
- e2e/README.md's CI/CD section now points at supportability-matrix.yml
  and describes its actual triggers (weekly schedule + manual dispatch)
  instead of the removed push-to-main workflow.
@vaishakdinesh
vaishakdinesh merged commit 81e2f86 into main Oct 9, 2026
11 checks passed
@vaishakdinesh
vaishakdinesh deleted the supportability-matrix-ci branch October 9, 2026 22:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants