Skip to content

fix(ci): migrate golangci-lint config to v2 schema and fix count-gated alarm outputs - #1137

Merged
cristim merged 1 commit into
mainfrom
fix/ci-failing-jobs
Jun 10, 2026
Merged

cristim merged 1 commit into
mainfrom
fix/ci-failing-jobs

Conversation

@cristim

@cristim cristim commented Jun 9, 2026

Copy link
Copy Markdown
Member

What

Fixes two of the failing CI - Build & Test jobs at their root cause. Both are config that drifted out of sync with what the rest of the repo already moved to.

Lint Code (was failing fast, ~6s)

CI pins golangci-lint v2.10.1 (deliberate, see commit 6f6fa3f24 "pin tool versions"), but .golangci.yml was still written for the v1 schema. The v2 binary rejects it instantly (reproduced locally):

can't load config: unsupported version of the configuration: ""

Migrated the config to the v2 schema with golangci-lint migrate (adds version: "2", moves settings under linters.settings, adds the exclusions/formatters blocks). Default-on linters (errcheck, govet, ineffassign, staticcheck, unused) are now implicit; exportloopref is dropped since v2 removed it (obsolete on Go 1.22+). No linter is disabled to mask findings.

Validate Terraform (aws) (was failing, ~21s)

PR #1130 added count = var.enable_migration_alarm ? 1 : 0 to the migration-alarm resources, but the module outputs still referenced them without an index, so terraform validate failed:

Error: Missing resource instance key
  on .../lambda/outputs.tf line 43, in output "migration_failed_alarm_arn":
  value = aws_cloudwatch_metric_alarm.migration_failed.arn

Wrapped both outputs in one(<resource>[*].<attr>) so they resolve to the single instance when enabled and null when disabled.

Verification (local)

  • golangci-lint run now parses the v2 config and lints (no more schema error).
  • terraform -chdir=terraform/environments/aws validate -> Success! The configuration is valid.
  • terraform fmt -check -recursive terraform/ -> clean.

Out of scope / needs follow-up

  • Security Scanning fails on real govulncheck findings: golang.org/x/net (GO-2026-5026 / GO-2026-4918) in providers/azure + providers/gcp, and google.golang.org/protobuf GO-2024-2611 in providers/gcp. The fix is dependency bumps (golang.org/x/net -> v0.55.0, protobuf -> v1.33.0+) which require network access to fetch the modules and their go.sum entries (unavailable in the working sandbox). Tracked for a separate PR.
  • E2E Tests is continue-on-error: true (non-blocking); already handled by ci: use docker compose v2 (fixes docker-compose command not found) #1135 (docker compose v2) plus the deliberate non-blocking guard for the not-yet-implemented Dockerfile.test. No change made.
  • Lint will surface pre-existing accumulated findings plus an integration-build-tag compile error (getMigrationsPath redeclared and a *float64 literal mismatch in internal/analytics/postgres_analytics_*_test.go) once the schema parses. Those are separate pre-existing problems (the compile error also fails the Integration Tests job) and need their own cleanup.

…d alarm outputs

Two CI failures share a root cause of config drifting from the tool/resource
shape the rest of the repo already moved to:

Lint Code job: CI pins golangci-lint v2.10.1 but .golangci.yml was still
written for the v1 schema, so the linter rejected it instantly with
"unsupported version of the configuration". Migrate the config to the v2
schema (version "2", linters.settings, exclusions, formatters block) via
`golangci-lint migrate`. Default-on linters (errcheck, govet, ineffassign,
staticcheck, unused) are now implicit; exportloopref is dropped as it was
removed in v2 (obsolete on Go 1.22+).

Validate Terraform (aws) job: the migration-failure alarm resources gained
`count = var.enable_migration_alarm ? 1 : 0`, but the module outputs still
referenced them without an index, so `terraform validate` failed with
"Missing resource instance key". Wrap both outputs in `one(...[*]...)` so
they resolve to the single instance when enabled and null when disabled.

Verified locally: `golangci-lint run` now parses the config and lints
(no more schema error); `terraform -chdir=terraform/environments/aws validate`
succeeds and `terraform fmt -check -recursive terraform/` is clean.
@cristim cristim added triaged Item has been triaged priority/p1 Next up; this sprint severity/high Significant harm type/bug Defect labels Jun 9, 2026
@coderabbitai

coderabbitai Bot commented Jun 9, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@cristim, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 31 minutes and 10 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 7416d613-6c84-472e-a01a-466ff0a32f61

📥 Commits

Reviewing files that changed from the base of the PR and between 5382322 and b54f06d.

📒 Files selected for processing (2)
  • .golangci.yml
  • terraform/modules/compute/aws/lambda/outputs.tf
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/ci-failing-jobs

Comment @coderabbitai help to get the list of available commands and usage tips.

@cristim
cristim merged commit 006aba9 into main Jun 10, 2026
11 of 16 checks passed
@cristim
cristim deleted the fix/ci-failing-jobs branch July 27, 2026 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority/p1 Next up; this sprint severity/high Significant harm triaged Item has been triaged type/bug Defect

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant