diff --git a/buildspec.yml b/buildspec.yml new file mode 100644 index 0000000..cd2f3aa --- /dev/null +++ b/buildspec.yml @@ -0,0 +1,11 @@ +version: 0.2 + +phases: + install: + runtime-versions: + nodejs: 22 + commands: + - npm ci + build: + commands: + - npx cdk deploy --require-approval never diff --git a/pipeline.yaml b/pipeline.yaml new file mode 100644 index 0000000..29f19bf --- /dev/null +++ b/pipeline.yaml @@ -0,0 +1,172 @@ +AWSTemplateFormatVersion: "2010-09-09" +Description: CI/CD pipeline — CodePipeline + CodeBuild for CDK deployments + +Parameters: + GitHubOwner: + Type: String + Default: Sea-Haven-Industries + GitHubRepo: + Type: String + Default: exec-aide + GitHubBranch: + Type: String + Default: main + ConnectionArn: + Type: String + Description: CodeConnections ARN for GitHub + Default: arn:aws:codeconnections:us-east-1:328440206208:connection/52bc9d0e-1088-43bc-9394-2c513ed10bc6 + +Resources: + ArtifactBucket: + Type: AWS::S3::Bucket + Properties: + BucketName: exec-aide-pipeline-artifacts + LifecycleConfiguration: + Rules: + - Id: expire-artifacts + Status: Enabled + ExpirationInDays: 30 + Tags: + - Key: Purpose + Value: pipeline-artifacts + - Key: ManagedBy + Value: !Ref AWS::StackName + + CodeBuildRole: + Type: AWS::IAM::Role + Properties: + RoleName: exec-aide-codebuild + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: codebuild.amazonaws.com + Action: sts:AssumeRole + Policies: + - PolicyName: codebuild-permissions + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - logs:CreateLogGroup + - logs:CreateLogStream + - logs:PutLogEvents + Resource: !Sub "arn:aws:logs:${AWS::Region}:${AWS::AccountId}:log-group:/aws/codebuild/exec-aide-build*" + - Effect: Allow + Action: + - s3:GetObject + - s3:PutObject + - s3:GetBucketLocation + Resource: + - !GetAtt ArtifactBucket.Arn + - !Sub "${ArtifactBucket.Arn}/*" + - Effect: Allow + Action: sts:AssumeRole + Resource: + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-deploy-role-${AWS::AccountId}-${AWS::Region}" + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-file-publishing-role-${AWS::AccountId}-${AWS::Region}" + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-lookup-role-${AWS::AccountId}-${AWS::Region}" + - !Sub "arn:aws:iam::${AWS::AccountId}:role/cdk-hnb659fds-cfn-exec-role-${AWS::AccountId}-${AWS::Region}" + + CodeBuildProject: + Type: AWS::CodeBuild::Project + Properties: + Name: exec-aide-build + Description: Build and deploy exec-aide CDK stack + ServiceRole: !GetAtt CodeBuildRole.Arn + Artifacts: + Type: CODEPIPELINE + Environment: + Type: ARM_CONTAINER + ComputeType: BUILD_GENERAL1_SMALL + Image: aws/codebuild/amazonlinux-aarch64-standard:3.0 + EnvironmentVariables: [] + PrivilegedMode: false + Source: + Type: CODEPIPELINE + BuildSpec: buildspec.yml + TimeoutInMinutes: 10 + + PipelineRole: + Type: AWS::IAM::Role + Properties: + RoleName: exec-aide-pipeline + AssumeRolePolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Principal: + Service: codepipeline.amazonaws.com + Action: sts:AssumeRole + Policies: + - PolicyName: pipeline-permissions + PolicyDocument: + Version: "2012-10-17" + Statement: + - Effect: Allow + Action: + - codeconnections:UseConnection + Resource: !Ref ConnectionArn + - Effect: Allow + Action: + - s3:GetObject + - s3:PutObject + - s3:GetBucketLocation + Resource: + - !GetAtt ArtifactBucket.Arn + - !Sub "${ArtifactBucket.Arn}/*" + - Effect: Allow + Action: + - codebuild:StartBuild + - codebuild:BatchGetBuilds + Resource: !GetAtt CodeBuildProject.Arn + + Pipeline: + Type: AWS::CodePipeline::Pipeline + Properties: + Name: exec-aide-pipeline + RoleArn: !GetAtt PipelineRole.Arn + ArtifactStore: + Type: S3 + Location: !Ref ArtifactBucket + Stages: + - Name: Source + Actions: + - Name: GitHub + ActionTypeId: + Category: Source + Owner: AWS + Provider: CodeStarSourceConnection + Version: "1" + Configuration: + ConnectionArn: !Ref ConnectionArn + FullRepositoryId: !Sub "${GitHubOwner}/${GitHubRepo}" + BranchName: !Ref GitHubBranch + DetectChanges: true + OutputArtifacts: + - Name: SourceOutput + + - Name: Build + Actions: + - Name: CDKDeploy + ActionTypeId: + Category: Build + Owner: AWS + Provider: CodeBuild + Version: "1" + Configuration: + ProjectName: !Ref CodeBuildProject + InputArtifacts: + - Name: SourceOutput + OutputArtifacts: + - Name: BuildOutput + +Outputs: + PipelineName: + Value: !Ref Pipeline + PipelineUrl: + Value: !Sub "https://${AWS::Region}.console.aws.amazon.com/codesuite/codepipeline/pipelines/${Pipeline}/view" + ArtifactBucketName: + Value: !Ref ArtifactBucket