From 082768ff51038fef40dccd39f12c1d041c9bd620 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 26 Jun 2026 20:17:17 -0400 Subject: [PATCH] ci: print stack outputs from CDK --outputs-file (drop describe-stacks) (#26) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cd-infra reported failure on every successful deploy: the 'Stack outputs' step ran 'aws cloudformation describe-stacks' with the githubdeploy-open-swe-infra- role, which intentionally lacks cloudformation:DescribeStacks. The cdk deploy itself succeeds (it reads outputs via the bootstrap cfn-exec role it assumes). Switch to 'cdk deploy --outputs-file cdk-outputs.json' + cat — no extra IAM grant, and the job goes green on actual deploy success instead of masking real failures behind a red run. --- .github/workflows/cd-infra.yml | 18 ++++++++++-------- .gitignore | 2 +- 2 files changed, 11 insertions(+), 9 deletions(-) diff --git a/.github/workflows/cd-infra.yml b/.github/workflows/cd-infra.yml index 61c29001..510bbe18 100644 --- a/.github/workflows/cd-infra.yml +++ b/.github/workflows/cd-infra.yml @@ -81,11 +81,13 @@ jobs: aws-region: us-east-1 - name: CDK deploy (dev only) working-directory: infra - run: npx cdk deploy OpenSweDevStack --require-approval never + # --outputs-file lets us print the stack outputs from CDK's own result + # (the deploy role intentionally lacks cloudformation:DescribeStacks; CDK + # gets outputs via the bootstrap cfn-exec role it assumes, so no extra grant). + run: npx cdk deploy OpenSweDevStack --require-approval never --outputs-file cdk-outputs.json - name: Stack outputs - run: | - aws cloudformation describe-stacks --stack-name open-swe-dev \ - --query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table + working-directory: infra + run: cat cdk-outputs.json deploy-prod: name: Deploy open-swe-prod @@ -115,8 +117,8 @@ jobs: aws-region: us-east-1 - name: CDK deploy (prod only) working-directory: infra - run: npx cdk deploy OpenSweProdStack --require-approval never + # See deploy-dev: --outputs-file avoids needing cloudformation:DescribeStacks. + run: npx cdk deploy OpenSweProdStack --require-approval never --outputs-file cdk-outputs.json - name: Stack outputs - run: | - aws cloudformation describe-stacks --stack-name open-swe-prod \ - --query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table + working-directory: infra + run: cat cdk-outputs.json diff --git a/.gitignore b/.gitignore index f3850d6f..5ea41695 100644 --- a/.gitignore +++ b/.gitignore @@ -71,4 +71,4 @@ __pycache__/ # Local working docs (gitignored — survives upstream merges, never pushed) TODO.md -# \ No newline at end of file +# infra/cdk-outputs.json