mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 06:53:15 +00:00
Merge pull request #23 from Sea-Haven-Industries/docs/fix-cd-sam-usage-example
Some checks are pending
ci / ci / ci (push) Waiting to run
Some checks are pending
ci / ci / ci (push) Waiting to run
docs(cicd): correct the cd-sam caller example to match the real contract
This commit is contained in:
commit
6786d63291
1 changed files with 14 additions and 1 deletions
15
cicd.md
15
cicd.md
|
|
@ -67,10 +67,23 @@ jobs:
|
|||
uses: Sea-Haven-Industries/.github/.github/workflows/cd-sam.yaml@<full-commit-sha> # main
|
||||
with:
|
||||
stack-name: "your-stack-name"
|
||||
cfn-role-arn: "arn:aws:iam::<account-id>:role/github-cfn-execution-role"
|
||||
secrets:
|
||||
cfn-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
||||
```
|
||||
|
||||
`cd-sam.yaml` takes two required inputs and one required secret. The two role ARNs are not interchangeable; they are different roles with different jobs:
|
||||
|
||||
| Name | Kind | Purpose |
|
||||
|---|---|---|
|
||||
| `stack-name` | input (`with:`) | The CloudFormation stack name |
|
||||
| `cfn-role-arn` | input (`with:`) | The **CloudFormation execution role** the stack is deployed *as*. This is `github-cfn-execution-role` in the repo's target account. Substitute that account's ID for `<account-id>`; the account must have the deploy substrate provisioned before the first deploy. Do not point new repos at the management account. |
|
||||
| `deploy-role-arn` | secret (`secrets:`) | The **OIDC role the workflow assumes**, from the repo's `AWS_DEPLOY_ROLE_ARN` secret (see [Authentication](#authentication)) |
|
||||
|
||||
Passing `cfn-role-arn` under `secrets:` fails: it is an input, so the run errors on an unexpected secret *and* a missing required input.
|
||||
|
||||
The remaining inputs have defaults and are only needed when a repo differs from them: `region` (`us-east-1`), `sam-template` (`template.yaml`), and `python-version` (`3.12`). The optional `parameter-overrides` secret passes `Key=Value` pairs through to `sam deploy`.
|
||||
|
||||
## Authentication
|
||||
|
||||
Deploy workflows authenticate to AWS via OIDC (no long-lived credentials). Each repo needs:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue