diff --git a/.gitignore b/.gitignore index 330d9aa..80fccd1 100644 --- a/.gitignore +++ b/.gitignore @@ -3,4 +3,5 @@ __pycache__/ .aws-sam/ venv/ .env +samconfig.toml output.json diff --git a/buildspec.yml b/buildspec.yml new file mode 100644 index 0000000..48d9d3d --- /dev/null +++ b/buildspec.yml @@ -0,0 +1,16 @@ +version: 0.2 + +phases: + install: + runtime-versions: + python: 3.12 + commands: + - pip install aws-sam-cli + build: + commands: + - sam build --template-file "$TEMPLATE_FILE" + - sam package --s3-bucket "$SAM_BUCKET" --output-template-file packaged.yaml + +artifacts: + files: + - packaged.yaml diff --git a/deployment-config.yaml b/deployment-config.yaml deleted file mode 100644 index 1b98211..0000000 --- a/deployment-config.yaml +++ /dev/null @@ -1,5 +0,0 @@ -template-file-path: template.yaml -parameters: - Timezone: America/New_York - SchedulerFunctionName: 3cx-ring-group-scheduler -tags: {} diff --git a/pipeline.yaml b/pipeline.yaml new file mode 100644 index 0000000..2a54030 --- /dev/null +++ b/pipeline.yaml @@ -0,0 +1,270 @@ +AWSTemplateFormatVersion: "2010-09-09" +Description: CI/CD pipeline — CodePipeline + CodeBuild for SAM deployments + +Parameters: + GitHubOwner: + Type: String + Default: Sea-Haven-Industries + GitHubRepo: + Type: String + Default: afterhours-shift-manager + GitHubBranch: + Type: String + Default: main + ConnectionArn: + Type: String + Description: CodeConnections ARN for GitHub + StackName: + Type: String + Default: afterhours-shift-manager + Description: Name of the SAM stack to deploy + TemplateFile: + Type: String + Default: template.yaml + SAMParameters: + Type: String + Default: "" + Description: "CloudFormation parameter overrides (e.g. Key1=Value1 Key2=Value2)" + +Resources: + ArtifactBucket: + Type: AWS::S3::Bucket + Properties: + BucketName: !Sub "${StackName}-pipeline-artifacts" + LifecycleConfiguration: + Rules: + - Id: expire-artifacts + Status: Enabled + ExpirationInDays: 30 + Tags: + - Key: Purpose + Value: pipeline-artifacts + - Key: ManagedBy + Value: !Ref AWS::StackName + + CodeBuildRole: + Type: AWS::IAM::Role + Properties: + RoleName: !Sub "${StackName}-codebuild" + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: codebuild.amazonaws.com + Action: sts:AssumeRole + Policies: + - PolicyName: codebuild-permissions + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - logs:CreateLogGroup + - logs:CreateLogStream + - logs:PutLogEvents + Resource: !Sub "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/${StackName}-build*" + - Effect: Allow + Action: + - s3:GetObject + - s3:PutObject + - s3:GetBucketLocation + Resource: + - !GetAtt ArtifactBucket.Arn + - !Sub "${ArtifactBucket.Arn}/*" + + CodeBuildProject: + Type: AWS::CodeBuild::Project + Properties: + Name: !Sub "${StackName}-build" + Description: !Sub "Build ${StackName} SAM application" + ServiceRole: !GetAtt CodeBuildRole.Arn + Artifacts: + Type: CODEPIPELINE + Environment: + Type: LINUX_CONTAINER + ComputeType: BUILD_GENERAL1_SMALL + Image: aws/codebuild/amazonlinux2-aarch64-standard:3.0 + EnvironmentVariables: + - Name: SAM_BUCKET + Value: !Ref ArtifactBucket + - Name: STACK_NAME + Value: !Ref StackName + - Name: TEMPLATE_FILE + Value: !Ref TemplateFile + - Name: SAM_PARAMETERS + Value: !Ref SAMParameters + Source: + Type: CODEPIPELINE + BuildSpec: buildspec.yml + TimeoutInMinutes: 10 + + CloudFormationRole: + Type: AWS::IAM::Role + Properties: + RoleName: !Sub "${StackName}-cfn-deploy" + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: cloudformation.amazonaws.com + Action: sts:AssumeRole + ManagedPolicyArns: + - arn:aws:iam::aws:policy/AWSLambda_FullAccess + - arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess + - arn:aws:iam::aws:policy/AmazonAPIGatewayAdministrator + - arn:aws:iam::aws:policy/AmazonEventBridgeFullAccess + - arn:aws:iam::aws:policy/IAMFullAccess + - arn:aws:iam::aws:policy/AWSCloudFormationFullAccess + Policies: + - PolicyName: s3-kms-ssm + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - s3:GetObject + - s3:GetBucketLocation + Resource: + - !GetAtt ArtifactBucket.Arn + - !Sub "${ArtifactBucket.Arn}/*" + - Effect: Allow + Action: + - ssm:GetParameter + - ssm:GetParameters + Resource: !Sub "arn:aws:ssm:${AWS::Region}:${AWS::AccountId}:parameter/*" + - Effect: Allow + Action: + - ses:SendEmail + Resource: !Sub "arn:aws:ses:${AWS::Region}:${AWS::AccountId}:identity/*" + + PipelineRole: + Type: AWS::IAM::Role + Properties: + RoleName: !Sub "${StackName}-pipeline" + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: codepipeline.amazonaws.com + Action: sts:AssumeRole + Policies: + - PolicyName: pipeline-permissions + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - codeconnections:UseConnection + Resource: !Ref ConnectionArn + - Effect: Allow + Action: + - s3:GetObject + - s3:PutObject + - s3:GetBucketLocation + Resource: + - !GetAtt ArtifactBucket.Arn + - !Sub "${ArtifactBucket.Arn}/*" + - Effect: Allow + Action: + - codebuild:StartBuild + - codebuild:BatchGetBuilds + Resource: !GetAtt CodeBuildProject.Arn + - Effect: Allow + Action: + - cloudformation:CreateStack + - cloudformation:UpdateStack + - cloudformation:DeleteStack + - cloudformation:DescribeStacks + - cloudformation:CreateChangeSet + - cloudformation:DeleteChangeSet + - cloudformation:DescribeChangeSet + - cloudformation:ExecuteChangeSet + - cloudformation:SetStackPolicy + Resource: + - !Sub "arn:aws:cloudformation:${AWS::Region}:${AWS::AccountId}:stack/${StackName}/*" + - Effect: Allow + Action: + - iam:PassRole + Resource: !GetAtt CloudFormationRole.Arn + + Pipeline: + Type: AWS::CodePipeline::Pipeline + Properties: + Name: !Sub "${StackName}-pipeline" + RoleArn: !GetAtt PipelineRole.Arn + ArtifactStore: + Type: S3 + Location: !Ref ArtifactBucket + Stages: + - Name: Source + Actions: + - Name: GitHub + ActionTypeId: + Category: Source + Owner: AWS + Provider: CodeStarSourceConnection + Version: "1" + Configuration: + ConnectionArn: !Ref ConnectionArn + FullRepositoryId: !Sub "${GitHubOwner}/${GitHubRepo}" + BranchName: !Ref GitHubBranch + DetectChanges: true + OutputArtifacts: + - Name: SourceOutput + + - Name: Build + Actions: + - Name: SAMBuild + ActionTypeId: + Category: Build + Owner: AWS + Provider: CodeBuild + Version: "1" + Configuration: + ProjectName: !Ref CodeBuildProject + InputArtifacts: + - Name: SourceOutput + OutputArtifacts: + - Name: BuildOutput + + - Name: Deploy + Actions: + - Name: CreateChangeSet + ActionTypeId: + Category: Deploy + Owner: AWS + Provider: CloudFormation + Version: "1" + Configuration: + ActionMode: CHANGE_SET_REPLACE + StackName: !Ref StackName + ChangeSetName: !Sub "${StackName}-changeset" + TemplatePath: BuildOutput::packaged.yaml + Capabilities: CAPABILITY_IAM,CAPABILITY_AUTO_EXPAND + RoleArn: !GetAtt CloudFormationRole.Arn + InputArtifacts: + - Name: BuildOutput + RunOrder: 1 + + - Name: ExecuteChangeSet + ActionTypeId: + Category: Deploy + Owner: AWS + Provider: CloudFormation + Version: "1" + Configuration: + ActionMode: CHANGE_SET_EXECUTE + StackName: !Ref StackName + ChangeSetName: !Sub "${StackName}-changeset" + RunOrder: 2 + +Outputs: + PipelineName: + Value: !Ref Pipeline + PipelineUrl: + Value: !Sub "https://${AWS::Region}.console.aws.amazon.com/codesuite/codepipeline/pipelines/${Pipeline}/view" + ArtifactBucketName: + Value: !Ref ArtifactBucket diff --git a/samconfig.toml b/samconfig.toml deleted file mode 100644 index c6afc26..0000000 --- a/samconfig.toml +++ /dev/null @@ -1,8 +0,0 @@ -version = 0.1 - -[default.deploy.parameters] -stack_name = "afterhours-shift-manager" -region = "us-east-1" -confirm_changeset = true -capabilities = "CAPABILITY_IAM" -resolve_s3 = true