.github/.github/workflows/cd-mobile-ios.yaml
Adam Moussa 8b8fc1ac46
ci: add job-level concurrency to the cd-cdk, cd-sam and iOS deploys
cd-dotnet-eb already serialises deploys per environment; the other three
deploy reusables had no concurrency group, so back-to-back merges could
start overlapping runs against the same target. CloudFormation rejects a
concurrent update on the same stack and cd-sam/cd-cdk pre-flight already
hard-fails on an in-progress stack, so the symptom is a failed run that
needs a manual re-run rather than a corrupted deploy. Grouping makes
those deploys queue instead.

Each group key names the thing being deployed, so independent targets in
one caller repo still deploy in parallel:

  cd-sam         region + stack-name (both always non-empty)
  cd-cdk         region + stacks + stack-name
  cd-mobile-ios  working-directory + fastlane-lane (both default)

cd-cdk keys on the stack selector rather than stack-name because
seahaven-org-baseline calls it from five jobs in a single run, one per
AWS account, and two of those pass no stack-name. Keying on stack-name
alone would collapse them into one group and serialise five independent
per-account deploys.

cancel-in-progress is false on all three, matching cd-dotnet-eb: unlike
CI, cancelling a deploy midway can leave infrastructure mid-update.
2026-07-28 12:35:26 -04:00

103 lines
3.3 KiB
YAML

name: CD — Mobile iOS (TestFlight)
on:
workflow_call:
inputs:
node-version:
description: "Node.js version to use"
type: string
default: "24"
ruby-version:
description: "Ruby version for Fastlane"
type: string
default: "3.3"
working-directory:
description: "Directory containing the mobile project"
type: string
default: "."
cache-dependency-path:
description: "Path to package-lock.json for npm cache"
type: string
default: "package-lock.json"
fastlane-lane:
description: "Fastlane lane to run"
type: string
default: "ios beta"
region:
description: "AWS region (for match S3 storage)"
type: string
default: "us-east-1"
timeout-minutes:
description: "Job timeout in minutes"
type: number
default: 45
secrets:
deploy-role-arn:
description: "OIDC deploy role ARN (for match S3 access)"
required: true
match-password:
description: "Encryption passphrase for match certificates"
required: true
asc-key-id:
description: "App Store Connect API key ID"
required: true
asc-issuer-id:
description: "App Store Connect API issuer ID"
required: true
asc-key-content:
description: "Base64-encoded App Store Connect API key (.p8)"
required: true
permissions:
id-token: write
contents: read
jobs:
deploy-ios:
runs-on: macos-26
timeout-minutes: ${{ inputs.timeout-minutes }}
# Serialise per app + lane so two pushes cannot upload over each other.
# There is no app-identifier input: the target is whatever Fastfile lives in
# working-directory, so that plus the lane is what identifies the deploy.
# Both always default ("." and "ios beta"), so the group is never empty.
# cancel-in-progress is FALSE on purpose: unlike CI, aborting midway can
# leave a half-uploaded TestFlight build.
concurrency:
group: cd-mobile-ios-${{ inputs.working-directory }}-${{ inputs.fastlane-lane }}
cancel-in-progress: false
defaults:
run:
working-directory: ${{ inputs.working-directory }}
steps:
- uses: actions/checkout@v7
- uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6
with:
role-to-assume: ${{ secrets.deploy-role-arn }}
aws-region: ${{ inputs.region }}
- uses: actions/setup-node@v7
with:
node-version: ${{ inputs.node-version }}
cache: npm
cache-dependency-path: ${{ inputs.cache-dependency-path }}
- uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1
with:
ruby-version: ${{ inputs.ruby-version }}
bundler-cache: true
working-directory: ${{ inputs.working-directory }}
- name: Install JS dependencies
run: npm ci
- name: Install CocoaPods
run: bundle exec pod install --project-directory=ios
- name: Build and upload
run: bundle exec fastlane ${{ inputs.fastlane-lane }}
env:
MATCH_PASSWORD: ${{ secrets.match-password }}
ASC_KEY_ID: ${{ secrets.asc-key-id }}
ASC_ISSUER_ID: ${{ secrets.asc-issuer-id }}
ASC_KEY_CONTENT: ${{ secrets.asc-key-content }}