From b54f06da31e51742f050b491b10f99e23c7a7a9a Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Tue, 9 Jun 2026 10:51:39 -0700 Subject: [PATCH] fix(ci): migrate golangci-lint config to v2 schema and fix count-gated alarm outputs Two CI failures share a root cause of config drifting from the tool/resource shape the rest of the repo already moved to: Lint Code job: CI pins golangci-lint v2.10.1 but .golangci.yml was still written for the v1 schema, so the linter rejected it instantly with "unsupported version of the configuration". Migrate the config to the v2 schema (version "2", linters.settings, exclusions, formatters block) via `golangci-lint migrate`. Default-on linters (errcheck, govet, ineffassign, staticcheck, unused) are now implicit; exportloopref is dropped as it was removed in v2 (obsolete on Go 1.22+). Validate Terraform (aws) job: the migration-failure alarm resources gained `count = var.enable_migration_alarm ? 1 : 0`, but the module outputs still referenced them without an index, so `terraform validate` failed with "Missing resource instance key". Wrap both outputs in `one(...[*]...)` so they resolve to the single instance when enabled and null when disabled. Verified locally: `golangci-lint run` now parses the config and lints (no more schema error); `terraform -chdir=terraform/environments/aws validate` succeeds and `terraform fmt -check -recursive terraform/` is clean. --- .golangci.yml | 208 ++++++++---------- .../modules/compute/aws/lambda/outputs.tf | 8 +- 2 files changed, 99 insertions(+), 117 deletions(-) diff --git a/.golangci.yml b/.golangci.yml index 0aaeda447..398857762 100644 --- a/.golangci.yml +++ b/.golangci.yml @@ -1,128 +1,110 @@ -# golangci-lint configuration for CUDly -# https://golangci-lint.run/usage/configuration/ - +version: "2" run: - timeout: 5m - tests: true build-tags: - integration - skip-dirs: - - vendor - - testdata - - .github - -output: - format: colored-line-number - print-issued-lines: true - print-linter-name: true - sort-results: true - + tests: true linters: enable: - - errcheck # Check for unchecked errors - - gosimple # Simplify code - - govet # Reports suspicious constructs - - ineffassign # Detects ineffectual assignments - - staticcheck # Go static analysis - - unused # Checks for unused constants, variables, functions and types - - gofmt # Checks if code is formatted - - goimports # Checks missing or unreferenced package imports - - misspell # Finds commonly misspelled English words - - revive # Fast, configurable, extensible linter - - gosec # Security-focused linter - - bodyclose # Checks HTTP response body is closed - - noctx # Finds http requests without context - - errorlint # Error wrapping issues - - exportloopref # Checks for pointers to enclosing loop variables - - gocritic # Provides diagnostics that check for bugs, performance and style issues - - gocyclo # Computes cyclomatic complexity - - godot # Checks if comments end in a period - - prealloc # Finds slice declarations that could potentially be pre-allocated - - unconvert # Removes unnecessary type conversions - - unparam # Reports unused function parameters - - whitespace # Checks for unnecessary newlines - -linters-settings: - errcheck: - check-type-assertions: true - check-blank: true - - govet: - check-shadowing: true - enable-all: true - - gocyclo: - min-complexity: 15 - - gocritic: - enabled-tags: - - diagnostic - - performance - - style - disabled-checks: - - dupImport - - ifElseChain - - octalLiteral - - whyNoLint - - gosec: - severity: medium - confidence: medium - excludes: - - G104 # Audit errors not checked (covered by errcheck) - config: - G101: # Look for hardcoded credentials - pattern: "(?i)passwd|pass|password|pwd|secret|token" - ignore_entropy: false - - revive: + - bodyclose + - errorlint + - gocritic + - gocyclo + - godot + - gosec + - misspell + - noctx + - prealloc + - revive + - unconvert + - unparam + - whitespace + settings: + errcheck: + check-type-assertions: true + check-blank: true + gocritic: + disabled-checks: + - dupImport + - ifElseChain + - octalLiteral + - whyNoLint + enabled-tags: + - diagnostic + - performance + - style + gocyclo: + min-complexity: 15 + gosec: + excludes: + - G104 + severity: medium + confidence: medium + config: + G101: + ignore_entropy: false + pattern: (?i)passwd|pass|password|pwd|secret|token + govet: + enable-all: true + misspell: + locale: US + revive: + rules: + - name: var-naming + disabled: false + - name: package-comments + disabled: true + - name: exported + disabled: false + - name: indent-error-flow + disabled: false + - name: error-return + disabled: false + - name: error-naming + disabled: false + - name: error-strings + disabled: false + exclusions: + generated: lax + presets: + - comments + - common-false-positives + - legacy + - std-error-handling rules: - - name: var-naming - disabled: false - - name: package-comments - disabled: true # We don't require package comments for internal packages - - name: exported - disabled: false - - name: indent-error-flow - disabled: false - - name: error-return - disabled: false - - name: error-naming - disabled: false - - name: error-strings - disabled: false - - misspell: - locale: US - + - linters: + - errcheck + - gocritic + - gocyclo + - gosec + path: _test\.go + - linters: + - errcheck + - gosec + path: internal/testutil/ + - linters: + - all + path: .*_gen\.go + paths: + - third_party$ + - builtin$ + - examples$ issues: - exclude-rules: - # Exclude test files from certain linters - - path: _test\.go - linters: - - gocyclo - - errcheck - - gosec - - gocritic - - # Exclude testutil package from certain checks - - path: internal/testutil/ - linters: - - errcheck - - gosec - - # Exclude generated code - - path: .*_gen\.go - linters: - - all - max-issues-per-linter: 0 max-same-issues: 0 new: false - severity: - default-severity: warning + default: warning rules: - linters: - gosec severity: error +formatters: + enable: + - gofmt + - goimports + exclusions: + generated: lax + paths: + - third_party$ + - builtin$ + - examples$ diff --git a/terraform/modules/compute/aws/lambda/outputs.tf b/terraform/modules/compute/aws/lambda/outputs.tf index badbafbdf..00145a4b0 100644 --- a/terraform/modules/compute/aws/lambda/outputs.tf +++ b/terraform/modules/compute/aws/lambda/outputs.tf @@ -39,11 +39,11 @@ output "signing_key_id" { } output "migration_failed_alarm_arn" { - description = "ARN of the CloudWatch alarm that fires when a database migration fails on cold start" - value = aws_cloudwatch_metric_alarm.migration_failed.arn + description = "ARN of the CloudWatch alarm that fires when a database migration fails on cold start (null when var.enable_migration_alarm is false)" + value = one(aws_cloudwatch_metric_alarm.migration_failed[*].arn) } output "migration_failed_metric_filter_name" { - description = "Name of the log metric filter counting migration-failure log lines" - value = aws_cloudwatch_log_metric_filter.migration_failed.name + description = "Name of the log metric filter counting migration-failure log lines (null when var.enable_migration_alarm is false)" + value = one(aws_cloudwatch_log_metric_filter.migration_failed[*].name) }