name: Infra CD # Path-filtered CDK deploy for /infra, per env, OIDC-only (no static keys). # # push to dev → CI (tsc+jest+synth) → deploy OpenSweDevStack (AUTO, CI-green-gated) # push to main → CI → deploy OpenSweProdStack (manual approval: env "prod") # # Why this is NOT the reusable cd-cdk.yaml: that workflow runs `cdk deploy --all`, # which would deploy ALL THREE stacks (incl. the OTHER env + the shared IAM stack) # from a single-env push — breaking the per-env dev/prod boundary. So we target one # stack explicitly per env. (Infra CI still uses the reusable ci-typescript-cdk.) # # The shared IAM stack (open-swe-iam — owns BOTH envs' OIDC deploy roles) is # intentionally NOT deployed here: it is a privileged, human-gated apply (T6), so a # routine dev push can never alter prod's deploy role. # # OIDC subject alignment (must match the per-env trust in infra/lib/config.ts): # - deploy-dev declares NO `environment:` → token sub = repo:…:ref:refs/heads/dev, # which is exactly what githubdeploy-open-swe-infra-dev trusts. # - deploy-prod declares `environment: prod` → token sub = repo:…:environment:prod, # which githubdeploy-open-swe-infra-prod trusts AND which triggers the GitHub # Environment's required-reviewer (manual approval) gate. # # Prerequisites (post-T6, when the roles exist): # - repo variables AWS_DEPLOY_ROLE_INFRA_DEV / AWS_DEPLOY_ROLE_INFRA_PROD = the # githubdeploy-open-swe-infra- role ARNs (open-swe-iam CfnOutputs). # - a GitHub Environment named "prod" with Adam as a required reviewer. permissions: contents: read on: push: branches: [dev, main] paths: - "infra/**" - ".github/workflows/cd-infra.yml" workflow_dispatch: concurrency: # one infra deploy per branch at a time; never cancel an in-flight deploy. group: cd-infra-${{ github.ref }} cancel-in-progress: false jobs: # CI-green precondition — re-run tsc + jest + synth on the pushed commit before # any deploy. A failure here blocks the deploy jobs (needs: ci). ci: name: Infra CI (pre-deploy) uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main with: node-version: "24" working-directory: infra cache-dependency-path: infra/package-lock.json run-typecheck: true run-tests: true run-cdk-synth: true deploy-dev: name: Deploy open-swe-dev needs: ci if: ${{ github.ref == 'refs/heads/dev' }} runs-on: ubuntu-latest timeout-minutes: 30 permissions: id-token: write contents: read steps: - uses: actions/checkout@v7 - uses: actions/setup-node@v4 with: node-version: "24" cache: npm cache-dependency-path: infra/package-lock.json - name: Install deps working-directory: infra run: npm ci - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_DEV }} aws-region: us-east-1 - name: CDK deploy (dev only) working-directory: infra # --outputs-file lets us print the stack outputs from CDK's own result # (the deploy role intentionally lacks cloudformation:DescribeStacks; CDK # gets outputs via the bootstrap cfn-exec role it assumes, so no extra grant). run: npx cdk deploy OpenSweDevStack --require-approval never --outputs-file cdk-outputs.json - name: Stack outputs working-directory: infra run: cat cdk-outputs.json deploy-prod: name: Deploy open-swe-prod needs: ci if: ${{ github.ref == 'refs/heads/main' }} runs-on: ubuntu-latest timeout-minutes: 30 # Manual-approval gate: the "prod" Environment requires a reviewer (Adam). # Also makes the OIDC sub …:environment:prod (matches the prod role trust). environment: prod permissions: id-token: write contents: read steps: - uses: actions/checkout@v7 - uses: actions/setup-node@v4 with: node-version: "24" cache: npm cache-dependency-path: infra/package-lock.json - name: Install deps working-directory: infra run: npm ci - uses: aws-actions/configure-aws-credentials@v6 with: role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_PROD }} aws-region: us-east-1 - name: CDK deploy (prod only) working-directory: infra # See deploy-dev: --outputs-file avoids needing cloudformation:DescribeStacks. run: npx cdk deploy OpenSweProdStack --require-approval never --outputs-file cdk-outputs.json - name: Stack outputs working-directory: infra run: cat cdk-outputs.json