ci: print stack outputs from CDK --outputs-file (drop describe-stacks) (#26)
Some checks are pending
Infra CD / Infra CI (pre-deploy) (push) Waiting to run
Infra CD / Deploy open-swe-dev (push) Blocked by required conditions
Infra CD / Deploy open-swe-prod (push) Blocked by required conditions

cd-infra reported failure on every successful deploy: the 'Stack outputs' step ran
'aws cloudformation describe-stacks' with the githubdeploy-open-swe-infra-<env> role,
which intentionally lacks cloudformation:DescribeStacks. The cdk deploy itself succeeds
(it reads outputs via the bootstrap cfn-exec role it assumes). Switch to
'cdk deploy --outputs-file cdk-outputs.json' + cat — no extra IAM grant, and the job
goes green on actual deploy success instead of masking real failures behind a red run.
This commit is contained in:
Adam Moussa 2026-06-26 20:17:17 -04:00 • committed by GitHub
parent f2633f9bd0
commit 082768ff51
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 11 additions and 9 deletions

View file

@ -81,11 +81,13 @@ jobs:
aws-region: us-east-1
- name: CDK deploy (dev only)
working-directory: infra
run: npx cdk deploy OpenSweDevStack --require-approval never
# --outputs-file lets us print the stack outputs from CDK's own result
# (the deploy role intentionally lacks cloudformation:DescribeStacks; CDK
# gets outputs via the bootstrap cfn-exec role it assumes, so no extra grant).
run: npx cdk deploy OpenSweDevStack --require-approval never --outputs-file cdk-outputs.json
- name: Stack outputs
run: |
aws cloudformation describe-stacks --stack-name open-swe-dev \
--query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table
working-directory: infra
run: cat cdk-outputs.json
deploy-prod:
name: Deploy open-swe-prod
@ -115,8 +117,8 @@ jobs:
aws-region: us-east-1
- name: CDK deploy (prod only)
working-directory: infra
run: npx cdk deploy OpenSweProdStack --require-approval never
# See deploy-dev: --outputs-file avoids needing cloudformation:DescribeStacks.
run: npx cdk deploy OpenSweProdStack --require-approval never --outputs-file cdk-outputs.json
- name: Stack outputs
run: |
aws cloudformation describe-stacks --stack-name open-swe-prod \
--query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table
working-directory: infra
run: cat cdk-outputs.json

2
.gitignore vendored
View file

@ -71,4 +71,4 @@ __pycache__/
# Local working docs (gitignored — survives upstream merges, never pushed)
TODO.md
#
# infra/cdk-outputs.json