Add GitHub Actions deploy workflow #28

Merged
amoussa1229 merged 3 commits from feature/add-deploy-workflow into main 2026-05-08 21:08:17 +00:00
amoussa1229 commented 2026-05-08 20:52:27 +00:00 (Migrated from github.com)

Summary

Adds OIDC-based deploy workflow that triggers on push to main. Uses the org-level reusable cd-cdk.yaml workflow with QEMU emulation for arm64 Docker builds. This will replace the existing CodePipeline once validated.

Validation

  • IAM deploy role provisioned via github-oidc-deploy-roles CloudFormation stack
  • AWS_DEPLOY_ROLE_ARN secret set on this repo
  • Reusable workflow merged to .github repo

Tests

Deploy will be validated on first merge to main.

Notes

  • QEMU enabled for PythonFunction arm64 Docker builds on x86 GitHub runners
  • Existing CodePipeline will be decommissioned after verifying this workflow deploys successfully
## Summary Adds OIDC-based deploy workflow that triggers on push to `main`. Uses the org-level reusable `cd-cdk.yaml` workflow with QEMU emulation for arm64 Docker builds. This will replace the existing CodePipeline once validated. ## Validation - IAM deploy role provisioned via `github-oidc-deploy-roles` CloudFormation stack - `AWS_DEPLOY_ROLE_ARN` secret set on this repo - Reusable workflow merged to `.github` repo ## Tests Deploy will be validated on first merge to `main`. ## Notes - QEMU enabled for PythonFunction arm64 Docker builds on x86 GitHub runners - Existing CodePipeline will be decommissioned after verifying this workflow deploys successfully
cursor[bot] commented 2026-05-08 20:52:34 +00:00 (Migrated from github.com)

PR Summary

Medium Risk
Introduces a new production deployment trigger on every push to main and assumes AWS credentials via OIDC, so misconfiguration could cause failed or unintended deploys. Scope is limited to CI configuration only.

Overview
Adds a new GitHub Actions Deploy workflow that runs on every push to main and serializes runs via a deploy concurrency group.

The job delegates deployment to the org reusable workflow cd-cdk.yaml, enabling QEMU for cross-arch builds and passing an AWS deploy role ARN via the AWS_DEPLOY_ROLE_ARN secret using OIDC (id-token: write).

Reviewed by Cursor Bugbot for commit 867e8509e3. Bugbot is set up for automated code reviews on this repo. Configure here.

## PR Summary <!-- CURSOR_SUMMARY --> **Medium Risk** Introduces a new production deployment trigger on every push to `main` and assumes AWS credentials via OIDC, so misconfiguration could cause failed or unintended deploys. Scope is limited to CI configuration only. **Overview** Adds a new GitHub Actions `Deploy` workflow that runs on every push to `main` and serializes runs via a `deploy` concurrency group. The job delegates deployment to the org reusable workflow `cd-cdk.yaml`, enabling QEMU for cross-arch builds and passing an AWS deploy role ARN via the `AWS_DEPLOY_ROLE_ARN` secret using OIDC (`id-token: write`). <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 867e8509e3c4ac481e8dd82cf1567b400de5d7ec. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
claude[bot] commented 2026-05-08 20:53:38 +00:00 (Migrated from github.com)

Looks good. Workflow follows the same org-internal reusable-workflow pattern as ci.yaml, OIDC role wired through a secret, and the QEMU toggle is appropriate for arm64 PythonFunction Docker builds on x86 runners. No issues to flag.

Looks good. Workflow follows the same org-internal reusable-workflow pattern as `ci.yaml`, OIDC role wired through a secret, and the QEMU toggle is appropriate for arm64 PythonFunction Docker builds on x86 runners. No issues to flag.
cursor[bot] (Migrated from github.com) reviewed 2026-05-08 20:53:52 +00:00
@ -0,0 +17,4 @@
with:
enable-qemu: true
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
cursor[bot] (Migrated from github.com) commented 2026-05-08 20:53:52 +00:00

Missing id-token: write permission breaks OIDC deploy

High Severity

This workflow uses OIDC-based AWS authentication via a reusable workflow (cd-cdk.yaml), but the caller workflow does not declare permissions: id-token: write. GitHub Actions requires the calling workflow to explicitly grant this permission — the reusable workflow's own permissions are constrained to the intersection with the caller's. Without it, the OIDC token request will fail and the deploy job will error out when attempting to assume the deploy-role-arn.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 1a17640003. Configure here.

### Missing `id-token: write` permission breaks OIDC deploy **High Severity** <!-- DESCRIPTION START --> This workflow uses OIDC-based AWS authentication via a reusable workflow (`cd-cdk.yaml`), but the caller workflow does not declare `permissions: id-token: write`. GitHub Actions requires the **calling** workflow to explicitly grant this permission — the reusable workflow's own permissions are constrained to the intersection with the caller's. Without it, the OIDC token request will fail and the deploy job will error out when attempting to assume the `deploy-role-arn`. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: e753fd60-54de-47bb-b35a-aac232f2052d --> <!-- LOCATIONS START .github/workflows/deploy.yaml#L1-L12 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjA0OTUxNGQzLTllOWQtNDI4Ny1iMWY1LTAzZjk0ZGE3YWZjNiIsImVuY3J5cHRpb25LZXkiOiJiUWNrV2JnR0NRR0ZBTEdhZGliSmY4V21IcnpBbTNYZ2dLM0RMUlRlQjRNIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6ImV4ZWMtYWlkZSJ9LCJpYXQiOjE3NzgyNzM2MzEsImV4cCI6MTc4MDg2NTYzMX0.w6HBC9G3-WeoWRcU3mzhOxwwBGEkHHlMN3zWK74FOmxol50jU-ncD_rkD8R8Rhtti8GRSYyyQyZ51FURlUneIiSa8eSlRGhdxNqAc4CHCx70bGbImdAu8VS0bfJSKojkBexv_htx1rB7vNAzUZxJPXmF2BHxAfvu6lS8NfImdhqhQGgVuQtPKxxz9Oy6Gs2FBOdMhZ6rmONPuX3jC6LRhRfYI3rdcEOs1vwVMyV7vjC52Umcj7v3gi6p1XVkw6xPdxfKxFkOUCRO9R2MuvXIuR1rgTUqZGiRXPP9HLa_AKs8DizAuW_5kMPmPRBeZFeZKb4R9NxCRV7X6sd8p7_nIw" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OjA0OTUxNGQzLTllOWQtNDI4Ny1iMWY1LTAzZjk0ZGE3YWZjNiIsImVuY3J5cHRpb25LZXkiOiJiUWNrV2JnR0NRR0ZBTEdhZGliSmY4V21IcnpBbTNYZ2dLM0RMUlRlQjRNIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6ImV4ZWMtYWlkZSIsInByTnVtYmVyIjoyOCwiY29tbWl0U2hhIjoiMWExNzY0MDAwMzc4NGM5NDhhOGY4YTJmZTMwNjQzYTUwMDg1NzdhNyIsInByb3ZpZGVyIjoiZ2l0aHViIn0sImlhdCI6MTc3ODI3MzYzMSwiZXhwIjoxNzgwODY1NjMxfQ.goRvvJtrUDp6wO9fK8fEkNzD4RXP6qxh7YKcnM2VT7tdkjWSH0OSIA9Co4hrG2HW0eFFdgks1WGjyc7QYTai10Q2P3UNUAArBaIakLdjU4iWf5AIqWuIrs7402nP7PDHyuy-ka3iDdHawYC36fjW9xP3v71Trd2lIPjDrcRZCVD2Ud3VmqTofLHy0ot1ypmHCQb0lmac_g46LvF2EDwQ0w95VNbuEN3MjgUr2aRmHUTxDhxhaG5FQtWY9Ym9o07Zu_lZLiLQ3V0_1UL70n_HkImY2F9xRQ4ZkQq5zibFgsPSRbzXulIp5_q1nzeyaBdWk_adsODo3JFEmkvyr4a5AQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 1a17640003784c948a8f8a2fe30643a5008577a7. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
claude[bot] commented 2026-05-08 20:57:45 +00:00 (Migrated from github.com)

Looks good. Clean OIDC setup with the right minimal permissions (id-token: write, contents: read), and the reusable-workflow pattern is consistent with the existing ci.yaml. The transitional overlap with the existing CodePipeline is acknowledged in the PR description, so nothing to flag there.

Looks good. Clean OIDC setup with the right minimal permissions (`id-token: write`, `contents: read`), and the reusable-workflow pattern is consistent with the existing `ci.yaml`. The transitional overlap with the existing CodePipeline is acknowledged in the PR description, so nothing to flag there.
cursor[bot] (Migrated from github.com) reviewed 2026-05-08 20:59:27 +00:00
cursor[bot] (Migrated from github.com) left a comment

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit f65c5fe3eb. Configure here.

<!-- BUGBOT_REVIEW --> Cursor Bugbot has reviewed your changes and found 1 potential issue. <!-- BUGBOT_FIX_ALL --> <a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9BTExfSU5fQ1VSU09SIiwiZGF0YSI6eyJyZWRpc0tleSI6ImJ1Z2JvdC1tdWx0aTpjYTFhZWYwYS05NGM2LTQ4OGYtOTNlZC04ODk5YjkxY2Q3NjUiLCJlbmNyeXB0aW9uS2V5IjoiNnp5YlpaUVlwb0FBNHA5QXA1MnFKdmlaTmQ2VmhWMjdfLW9keE9yeDh2dyIsImJyYW5jaCI6ImZlYXR1cmUvYWRkLWRlcGxveS13b3JrZmxvdyIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJleGVjLWFpZGUifSwiaWF0IjoxNzc4MjczOTY3LCJleHAiOjE3ODA4NjU5Njd9.w-3g6_VueNlfJNM0jNttStAc0ySdvEh5NC0Enpv_LN_O981-uZSXlNAzSlAlLaQAYWjjHMTSwiWBZmWsiFO7gkIRs2oJQnFAg28MBzpyJq4S0hdDViVPXW4Qhdnmo38fcHNuEX6jnEygFYJAfWUC21so8ssqGisKDhH5H6b-GpVj1RbQg0hKWnHcvuwoxqqTv21aIeUyOuIxm3JnjXdXfs92c8nkCBQc3a9rgTCwM0-UJXGqy6H5r3Vmmqa8mW_ke388faL83rWQXkREFvAFrDoiPZuVmp57nT0Z8b9O5PXQcVNxl_5qmBVG2YI-D6rHn7qc1ckqU5L84kmfxi-GBA" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix All in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a> <!-- /BUGBOT_FIX_ALL --> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_BEGIN --> <sup>❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the [Cursor dashboard](https://www.cursor.com/dashboard/bugbot).</sup> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_END --> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit f65c5fe3eb8e22c7ed8155d0e9951d48be2cd7d3. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
@ -0,0 +17,4 @@
with:
enable-qemu: true
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
cursor[bot] (Migrated from github.com) commented 2026-05-08 20:59:28 +00:00

Missing concurrency control risks parallel deploy failures

Medium Severity

This deploy workflow lacks a concurrency group. The CodePipeline it replaces (in pipeline.yaml) natively serializes executions, but GitHub Actions does not — rapid successive merges to main trigger parallel runs. CloudFormation rejects concurrent stack updates, so the second cdk deploy would fail, leaving the latest changes undeployed with no automatic retry.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit f65c5fe3eb. Configure here.

### Missing concurrency control risks parallel deploy failures **Medium Severity** <!-- DESCRIPTION START --> This deploy workflow lacks a `concurrency` group. The CodePipeline it replaces (in `pipeline.yaml`) natively serializes executions, but GitHub Actions does not — rapid successive merges to `main` trigger parallel runs. CloudFormation rejects concurrent stack updates, so the second `cdk deploy` would fail, leaving the latest changes undeployed with no automatic retry. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: ref1_ee430734-7e84-4da7-be37-35a2aba2ee21 --> <!-- LOCATIONS START .github/workflows/deploy.yaml#L1-L16 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmM0YzM4ODM5LTJmODQtNDBlMC1iMzY1LTM4NTIyZWJjZDc5NiIsImVuY3J5cHRpb25LZXkiOiI0bjlZQUhmMFZPdUR5bW5LbHA2eFc5N2pNN3RvTmFPakVNbU02NURPSkVJIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6ImV4ZWMtYWlkZSJ9LCJpYXQiOjE3NzgyNzM5NjcsImV4cCI6MTc4MDg2NTk2N30.oSWN5zyV6VgbT_jS9EAIkfX2RugVSof5jLzv1fL9UuCz1dso2-HT21DQzAZFEEuTh4IHSJIYXi5pDGPeKElRvHcKyTZzdLuRZnlLLliwCCTdIFWIcp6ijP1gJijYWsEpqzVwR18pe7j52dWnJWplltYsvu2KsZ2bWNqUSqvjQikaVIx0C1LQe4pkCvJw1bl_YElHNqKAxwQA3KWycyTmS-o0N7T6tRIQ82WvlGnHQdCik4mnlh3_jCCopl_GvHsYwxwCTnxel1imp3dAvf94e_iBXO6cXF1ODy34wQw_Xosu-zoH4QzoPmVpYnWucRV0lkUCv8eJOyjFLbnibBJ-Xw" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmM0YzM4ODM5LTJmODQtNDBlMC1iMzY1LTM4NTIyZWJjZDc5NiIsImVuY3J5cHRpb25LZXkiOiI0bjlZQUhmMFZPdUR5bW5LbHA2eFc5N2pNN3RvTmFPakVNbU02NURPSkVJIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6ImV4ZWMtYWlkZSIsInByTnVtYmVyIjoyOCwiY29tbWl0U2hhIjoiZjY1YzVmZTNlYjhlMjJjN2VkODE1NWQwZTk5NTFkNDhiZTJjZDdkMyIsInByb3ZpZGVyIjoiZ2l0aHViIn0sImlhdCI6MTc3ODI3Mzk2NywiZXhwIjoxNzgwODY1OTY3fQ.yIPiMedF-HnW6iBKDTvL03bDx8DQG4XWDoK1x1Emu9iy2djvye30nrM1xBbmGIlqBvJrDtNlCdjWm1H6YaOANKgty3ZDOMULpRZpfd_rR2NpRCV5_GVr0PjUIaM2C9xHRUwC4HnBOM4-aqzfnsWzVWwIsvyE-bJ-__YC8-0_KyIZGgF7VVxe8AxH2R2wBXOseze5dg0pzAN3AlT1fWTGRGphljrg69yb-Fm0aUeQGof_kHnqLv3prjsl3LLfcd1pl9sCuSD5vw1uYnPTpze9JpjnpQD6RSGoVro7RFGyiARZxBym7dFgnvhhKr_9Y6oDq46Lko4BwiR4SVBshCwdIg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit f65c5fe3eb8e22c7ed8155d0e9951d48be2cd7d3. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
claude[bot] commented 2026-05-08 21:02:45 +00:00 (Migrated from github.com)

Looks good. OIDC-based auth with minimal permissions, concurrency control to prevent overlapping deploys, and consistent with the existing ci.yaml reusable-workflow pattern. No issues found.

Looks good. OIDC-based auth with minimal permissions, concurrency control to prevent overlapping deploys, and consistent with the existing `ci.yaml` reusable-workflow pattern. No issues found.
This repo is archived. You cannot comment on pull requests.
No description provided.