Add GitHub Actions deploy workflow #28
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
python
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/exec-aide#28
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/add-deploy-workflow"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds OIDC-based deploy workflow that triggers on push to
main. Uses the org-level reusablecd-cdk.yamlworkflow with QEMU emulation for arm64 Docker builds. This will replace the existing CodePipeline once validated.Validation
github-oidc-deploy-rolesCloudFormation stackAWS_DEPLOY_ROLE_ARNsecret set on this repo.githubrepoTests
Deploy will be validated on first merge to
main.Notes
PR Summary
Medium Risk
Introduces a new production deployment trigger on every push to
mainand assumes AWS credentials via OIDC, so misconfiguration could cause failed or unintended deploys. Scope is limited to CI configuration only.Overview
Adds a new GitHub Actions
Deployworkflow that runs on every push tomainand serializes runs via adeployconcurrency group.The job delegates deployment to the org reusable workflow
cd-cdk.yaml, enabling QEMU for cross-arch builds and passing an AWS deploy role ARN via theAWS_DEPLOY_ROLE_ARNsecret using OIDC (id-token: write).Reviewed by Cursor Bugbot for commit
867e8509e3. Bugbot is set up for automated code reviews on this repo. Configure here.Looks good. Workflow follows the same org-internal reusable-workflow pattern as
ci.yaml, OIDC role wired through a secret, and the QEMU toggle is appropriate for arm64 PythonFunction Docker builds on x86 runners. No issues to flag.@ -0,0 +17,4 @@with:enable-qemu: truesecrets:deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}Missing
id-token: writepermission breaks OIDC deployHigh Severity
This workflow uses OIDC-based AWS authentication via a reusable workflow (
cd-cdk.yaml), but the caller workflow does not declarepermissions: id-token: write. GitHub Actions requires the calling workflow to explicitly grant this permission — the reusable workflow's own permissions are constrained to the intersection with the caller's. Without it, the OIDC token request will fail and the deploy job will error out when attempting to assume thedeploy-role-arn.Reviewed by Cursor Bugbot for commit
1a17640003. Configure here.Looks good. Clean OIDC setup with the right minimal permissions (
id-token: write,contents: read), and the reusable-workflow pattern is consistent with the existingci.yaml. The transitional overlap with the existing CodePipeline is acknowledged in the PR description, so nothing to flag there.Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit
f65c5fe3eb. Configure here.@ -0,0 +17,4 @@with:enable-qemu: truesecrets:deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}Missing concurrency control risks parallel deploy failures
Medium Severity
This deploy workflow lacks a
concurrencygroup. The CodePipeline it replaces (inpipeline.yaml) natively serializes executions, but GitHub Actions does not — rapid successive merges tomaintrigger parallel runs. CloudFormation rejects concurrent stack updates, so the secondcdk deploywould fail, leaving the latest changes undeployed with no automatic retry.Reviewed by Cursor Bugbot for commit
f65c5fe3eb. Configure here.Looks good. OIDC-based auth with minimal permissions, concurrency control to prevent overlapping deploys, and consistent with the existing
ci.yamlreusable-workflow pattern. No issues found.