From bf14925fcfac8064868e1b96f64e298894d4f10d Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Thu, 24 Sep 2026 16:49:49 +0000 Subject: [PATCH] feat(ci): derive Fargate health URL from CloudFront (#150) Callers that cannot add an SSM parameter to a shared permissions boundary can set health-from-distribution. The default still reads SSM api-url. --- .github/workflows/cd-hcp-fargate.yaml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/.github/workflows/cd-hcp-fargate.yaml b/.github/workflows/cd-hcp-fargate.yaml index c766504..b4c6c55 100644 --- a/.github/workflows/cd-hcp-fargate.yaml +++ b/.github/workflows/cd-hcp-fargate.yaml @@ -87,6 +87,11 @@ on: type: number required: false default: 6 + health-from-distribution: + description: "Build the health URL from SSM distribution-id and CloudFront GetDistribution. Leave false to read SSM api-url." + type: boolean + required: false + default: false concurrency-suffix: description: "Optional concurrency group suffix when two deployables share an SSM prefix" type: string @@ -221,6 +226,7 @@ jobs: id: deploy env: SSM_PREFIX: ${{ inputs.ssm-prefix }} + HEALTH_FROM_DISTRIBUTION: ${{ inputs.health-from-distribution }} run: | set -euo pipefail get_param() { @@ -232,7 +238,13 @@ jobs: FAMILY=$(get_param "${prefix}/task-family") ECR=$(get_param "${prefix}/ecr-repository") CONTAINER=$(get_param "${prefix}/container-name") - API_URL=$(get_param "${prefix}/api-url") + if [ "${HEALTH_FROM_DISTRIBUTION}" = "true" ]; then + DIST_ID=$(get_param "${prefix}/distribution-id") + DOMAIN=$(aws cloudfront get-distribution --id "${DIST_ID}" --query Distribution.DomainName --output text) + API_URL="https://${DOMAIN}" + else + API_URL=$(get_param "${prefix}/api-url") + fi { echo "cluster=${CLUSTER}" echo "service=${SERVICE}"