diff --git a/.github/workflows/cd-cdk.yaml b/.github/workflows/cd-cdk.yaml index 6a12f41..510cc45 100644 --- a/.github/workflows/cd-cdk.yaml +++ b/.github/workflows/cd-cdk.yaml @@ -134,7 +134,12 @@ jobs: - name: Post-deploy script if: ${{ inputs.post-deploy-script != '' }} - run: bash ${{ inputs.post-deploy-script }} + # Env-var indirection (not inline expression interpolation) so shell + # metacharacters in the input are never parsed as script; the input is a + # single script path, so $POST_DEPLOY_SCRIPT is quoted (no word-split). + env: + POST_DEPLOY_SCRIPT: ${{ inputs.post-deploy-script }} + run: bash "$POST_DEPLOY_SCRIPT" - name: Post-deploy health check if: ${{ inputs.stack-name != '' }} diff --git a/.github/workflows/cd-sam.yaml b/.github/workflows/cd-sam.yaml index 249998b..5628911 100644 --- a/.github/workflows/cd-sam.yaml +++ b/.github/workflows/cd-sam.yaml @@ -80,10 +80,15 @@ jobs: run: sam build --template ${{ inputs.sam-template }} - name: SAM deploy + # Env-var indirection (not inline expression interpolation) so shell + # metacharacters in the secret are never parsed as script; unquoted + # $PARAM_OVERRIDES deliberately word-splits multiple Key=Value pairs. + env: + PARAM_OVERRIDES: ${{ secrets.parameter-overrides }} run: | PARAMS="" - if [ -n "${{ secrets.parameter-overrides }}" ]; then - PARAMS="--parameter-overrides ${{ secrets.parameter-overrides }}" + if [ -n "$PARAM_OVERRIDES" ]; then + PARAMS="--parameter-overrides $PARAM_OVERRIDES" fi sam deploy \ --stack-name ${{ inputs.stack-name }} \