mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-10-04 20:42:05 +00:00
* chore(deps): bump pyjwt in /tests in the pip group across 1 directory Bumps the pip group with 1 update in the /tests directory: [pyjwt](https://github.com/jpadilla/pyjwt). Updates `pyjwt` from 2.14.0 to 2.15.0 - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com> * fix: update org workflow SHA pins to latest version * test(infra): expect org workflow pins at v1.0.21 The contract tests still asserted the v1.0.19 SHA after the workflow pin bump, so CI failed on the PyJWT bump PR. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Adam Moussa <adam@seahavenind.com>
70 lines
2.2 KiB
YAML
70 lines
2.2 KiB
YAML
name: Deploy API
|
|
|
|
# Fargate image CD (PLAT-216). GitHub Actions builds the Flask image, pushes to ECR,
|
|
# and registers a new task definition. Terraform owns the cluster, service,
|
|
# ALB, and ignores container_definitions / task_definition.
|
|
#
|
|
# push to main -> dev, at github.sha
|
|
# release: published -> prod, at the release tag
|
|
# workflow_dispatch -> chosen environment at a chosen ref
|
|
#
|
|
# Releases are cut by a human with `gh release create vX.Y.Z --target main`.
|
|
# Nothing here creates an HCP run.
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths-ignore:
|
|
- "terraform/**"
|
|
- "docs/**"
|
|
- "*.md"
|
|
- ".github/workflows/ci.yaml"
|
|
- ".github/workflows/labeler.yml"
|
|
- ".github/workflows/dependency-review.yml"
|
|
release:
|
|
types: [published]
|
|
workflow_dispatch:
|
|
inputs:
|
|
environment:
|
|
description: "Target Environment"
|
|
required: true
|
|
type: choice
|
|
options: [dev, prod]
|
|
ref:
|
|
description: "Git ref to build and deploy (tag, branch, or SHA). Empty means the workflow ref."
|
|
required: false
|
|
type: string
|
|
default: ""
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy-dev:
|
|
name: Deploy API to dev
|
|
if: github.event_name == 'push' || (github.event_name == 'workflow_dispatch' && inputs.environment == 'dev')
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
secrets: inherit
|
|
with:
|
|
environment: dev
|
|
ref: ${{ inputs.ref }}
|
|
ssm-prefix: /afterhours-shift-manager/deploy
|
|
docker-platform: linux/arm64
|
|
|
|
deploy-prod:
|
|
name: Deploy API to prod
|
|
if: github.event_name == 'release' || (github.event_name == 'workflow_dispatch' && inputs.environment == 'prod')
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-fargate.yaml@47185fa602dffddb8297db5f3525d7c9bc05d7cd # v1.0.21
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
secrets: inherit
|
|
with:
|
|
environment: prod
|
|
ref: ${{ github.event.release.tag_name || inputs.ref }}
|
|
ssm-prefix: /afterhours-shift-manager/deploy
|
|
docker-platform: linux/arm64
|
|
ship-gate: true
|