From 242d02bd8fc19ab5216ee185c40a12ad6cf161c4 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 14 May 2026 18:31:51 -0400 Subject: [PATCH] Add pre-flight stack status checks to CD workflows Blocks deploy if the CloudFormation stack is in ROLLBACK_COMPLETE, FAILED, or IN_PROGRESS state. Prevents wasted deploy attempts on stacks that need manual intervention. --- .github/workflows/cd-cdk.yaml | 28 ++++++++++++++++++++++++++++ .github/workflows/cd-sam.yaml | 23 +++++++++++++++++++++++ 2 files changed, 51 insertions(+) diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index 191fbf2..65e473b 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -23,6 +23,10 @@ on: description: "Enable QEMU for cross-platform Docker builds (arm64 on x86 runners)" type: boolean default: false + stack-name: + description: "CloudFormation stack name (for pre-flight checks)" + type: string + default: "" secrets: deploy-role-arn: description: "OIDC deploy role ARN" @@ -67,6 +71,30 @@ jobs: role-to-assume: ${{ secrets.deploy-role-arn }} aws-region: ${{ inputs.region }} + - name: Pre-flight checks + if: ${{ inputs.stack-name != '' }} + run: | + echo "Pre-flight: checking stack ${{ inputs.stack-name }}..." + STATUS=$(aws cloudformation describe-stacks \ + --stack-name "${{ inputs.stack-name }}" \ + --query 'Stacks[0].StackStatus' --output text 2>/dev/null || echo "NOT_FOUND") + case "$STATUS" in + *ROLLBACK_COMPLETE|*FAILED) + echo "::error::Stack ${{ inputs.stack-name }} is in $STATUS — manual intervention required." + exit 1 + ;; + *IN_PROGRESS) + echo "::error::Stack ${{ inputs.stack-name }} has an operation in progress ($STATUS) — wait for it to complete." + exit 1 + ;; + NOT_FOUND) + echo "Pre-flight: stack not found — will be created on first deploy." + ;; + *) + echo "Pre-flight: stack status is $STATUS — OK to deploy." + ;; + esac + - name: CDK deploy working-directory: ${{ inputs.cdk-dir }} run: npx -y cdk deploy --all --require-approval never diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index e5a53d3..713df93 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -53,6 +53,29 @@ jobs: role-to-assume: ${{ secrets.deploy-role-arn }} aws-region: ${{ inputs.region }} + - name: Pre-flight checks + run: | + echo "Pre-flight: checking stack ${{ inputs.stack-name }}..." + STATUS=$(aws cloudformation describe-stacks \ + --stack-name "${{ inputs.stack-name }}" \ + --query 'Stacks[0].StackStatus' --output text 2>/dev/null || echo "NOT_FOUND") + case "$STATUS" in + *ROLLBACK_COMPLETE|*FAILED) + echo "::error::Stack ${{ inputs.stack-name }} is in $STATUS — manual intervention required." + exit 1 + ;; + *IN_PROGRESS) + echo "::error::Stack ${{ inputs.stack-name }} has an operation in progress ($STATUS) — wait for it to complete." + exit 1 + ;; + NOT_FOUND) + echo "Pre-flight: stack not found — will be created on first deploy." + ;; + *) + echo "Pre-flight: stack status is $STATUS — OK to deploy." + ;; + esac + - name: SAM build run: sam build --template ${{ inputs.sam-template }}