#!/usr/bin/env bash # Provision a new Sea Haven Industries repo with all required infrastructure. # Usage: ./provision-repo.sh [sam|cdk] # # Creates: GitHub repo, OIDC deploy role, repo secret, security features, # and CI/CD workflow stubs. # # Workflow callers are generated from the latest released version of the # Sea-Haven-Industries/.github repository and pinned to its full commit SHA. set -euo pipefail REPO_NAME="${1:?Usage: provision-repo.sh [sam|cdk]}" STACK_TYPE="${2:-sam}" ORG="Sea-Haven-Industries" ACCOUNT_ID="328440206208" REGION="us-east-1" OIDC_PROVIDER="arn:aws:iam::${ACCOUNT_ID}:oidc-provider/token.actions.githubusercontent.com" ROLE_NAME="githubdeploy-${REPO_NAME}" if [[ ! "$REPO_NAME" =~ ^[a-z0-9]([a-z0-9-]*[a-z0-9])?$ ]]; then echo "Error: repo name must be kebab-case (lowercase, hyphens only, no leading/trailing hyphens)" exit 1 fi WORKFLOW_VERSION=$(gh api "repos/${ORG}/.github/tags?per_page=100" \ --jq '[.[] | select(.name | test("^v[0-9]+\\.[0-9]+\\.[0-9]+$"))][0].name // empty') if [[ -z "$WORKFLOW_VERSION" ]]; then echo "Error: no released Sea-Haven-Industries/.github vX.Y.Z tag found." exit 1 fi WORKFLOW_SHA=$(gh api "repos/${ORG}/.github/commits/${WORKFLOW_VERSION}" --jq .sha) if [[ ! "$WORKFLOW_SHA" =~ ^[0-9a-f]{40}$ ]]; then echo "Error: ${WORKFLOW_VERSION} did not resolve to a full commit SHA." exit 1 fi echo "=== Provisioning ${ORG}/${REPO_NAME} (${STACK_TYPE}) ===" echo "Workflow release: ${WORKFLOW_VERSION} (${WORKFLOW_SHA})" # 1. Create GitHub repo echo "" echo "[1/5] Creating GitHub repo..." if gh repo view "${ORG}/${REPO_NAME}" &>/dev/null; then echo " Repo already exists — skipping." else gh repo create "${ORG}/${REPO_NAME}" \ --private \ --description "${REPO_NAME} — Sea Haven Industries" \ --clone=false echo " Created ${ORG}/${REPO_NAME}" fi # 2. Create OIDC deploy role echo "" echo "[2/5] Creating IAM deploy role: ${ROLE_NAME}..." TRUST_POLICY=$(cat </dev/null; then echo " Role already exists — skipping." else aws iam create-role \ --role-name "${ROLE_NAME}" \ --assume-role-policy-document "${TRUST_POLICY}" \ --tags "Key=Project,Value=${REPO_NAME}" "Key=ManagedBy,Value=provision-script" \ --query 'Role.Arn' --output text if [[ "$STACK_TYPE" == "cdk" ]]; then DEPLOY_POLICY=$(cat </dev/null || true gh api "repos/${ORG}/${REPO_NAME}" -X PATCH \ -f security_and_analysis.dependabot_security_updates.status=enabled \ -f security_and_analysis.secret_scanning.status=enabled \ --silent 2>/dev/null || true echo " Dependabot alerts, security updates, and secret scanning enabled." # 5. Create CI/CD workflow stubs echo "" echo "[5/5] Creating CI/CD workflow files..." REPO_DIR="${HOME}/Documents/repositories/${REPO_NAME}" if [[ ! -d "${REPO_DIR}" ]]; then echo " Repo not cloned locally — skipping workflow file creation." echo " Clone it and re-run, or create .github/workflows/ manually." else mkdir -p "${REPO_DIR}/.github/workflows" if [[ "$STACK_TYPE" == "cdk" ]]; then cat > "${REPO_DIR}/.github/workflows/ci.yaml" < "${REPO_DIR}/.github/workflows/deploy.yaml" < "${REPO_DIR}/.github/workflows/ci.yaml" < "${REPO_DIR}/.github/workflows/deploy.yaml" <