.github/workflow-templates/sam-deploy.yml
Adam Moussa 5a5ab684f6
ci(templates): replace hardcoded management-account role ARN with placeholder
The sam-deploy starter template pointed every new repo's cfn-role-arn at
the management account's execution role, silently landing new workloads
in an account frozen for workloads. The ARN is now a REPLACE-ME
placeholder with guidance to use the github-cfn-execution-role in the
repo's target account.
2026-07-27 16:03:25 -04:00

20 lines
916 B
YAML

name: Deploy (SAM)
on:
push:
branches: [main]
jobs:
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@555d07c3a240689a81668026787eba089df4c975 # main
with:
# Required: the CloudFormation stack name (kebab-case, matches repo name).
# NOTE: this is a literal placeholder on purpose — starter-workflow variables
# like $default-branch substitute to the BRANCH name ("main"), not the repo name.
stack-name: REPLACE-ME-stack-name
# Required: the CloudFormation execution role ARN for this stack — the
# github-cfn-execution-role in the repo's TARGET account (part of the
# per-account deploy substrate; the account must have it provisioned
# before first deploy). Do not point new repos at the management account.
cfn-role-arn: REPLACE-ME-cfn-role-arn
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}