mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-10-01 05:03:15 +00:00
* ci: path-filtered infra CI/CD with dual OIDC roles + prod approval gate (T18)
Add the /infra half of the combined-repo pipeline (the Python agent keeps ci.yml):
- ci-infra.yml — PR check on infra/** : tsc + jest + cdk synth via the org
reusable ci-typescript-cdk.yaml (working-directory: infra).
- cd-infra.yml — push to dev/main on infra/** (or dispatch):
* job 'ci' (reusable) is the CI-green precondition (deploy needs: ci).
* deploy-dev (ref=dev, NO environment) → cdk deploy OpenSweDevStack,
assuming githubdeploy-open-swe-infra-dev (OIDC sub ref:refs/heads/dev). AUTO.
* deploy-prod (ref=main, environment: prod) → cdk deploy OpenSweProdStack,
assuming githubdeploy-open-swe-infra-prod (OIDC sub environment:prod). The
'prod' Environment's required reviewer is the manual-approval gate.
Deliberately self-contained (NOT the reusable cd-cdk.yaml) because that runs
'cdk deploy --all' — from a single-env push it would deploy the other env + the
shared IAM stack, breaking the per-env boundary. CD targets one stack per env;
the shared open-swe-iam stack is human-gated (T6), never deployed by CD.
Infra CI is enforced at the DEPLOY boundary (deploy jobs need ci), not as a
branch-protection required check — path-filtering a required check would deadlock
app-only PRs. Documented in infra/README.md along with the post-T6 prerequisites
(repo vars AWS_DEPLOY_ROLE_INFRA_{DEV,PROD}; a 'prod' Environment w/ reviewer).
Not active until the IAM roles are applied (T6) — assuming a nonexistent role
just fails closed. App-side CD (S3 artifact + SSM) is T19.
* fix(infra): commit jest.config.js (was ignored by *.js → infra CI used Babel)
The infra/.gitignore *.js rule (for compiled CDK output) silently swept up the
hand-authored jest.config.js, so it was never committed. Local jest passed (file
present in the working tree) but CI's fresh checkout lacked it → jest fell back to
the default Babel transform → 'Cannot use import statement outside a module' on the
TypeScript test. Surfaced now because T18 is the first workflow to run infra jest
in CI. Negate the ignore for this one file and commit it.
122 lines
4.5 KiB
YAML
122 lines
4.5 KiB
YAML
name: Infra CD
|
|
|
|
# Path-filtered CDK deploy for /infra, per env, OIDC-only (no static keys).
|
|
#
|
|
# push to dev → CI (tsc+jest+synth) → deploy OpenSweDevStack (AUTO, CI-green-gated)
|
|
# push to main → CI → deploy OpenSweProdStack (manual approval: env "prod")
|
|
#
|
|
# Why this is NOT the reusable cd-cdk.yaml: that workflow runs `cdk deploy --all`,
|
|
# which would deploy ALL THREE stacks (incl. the OTHER env + the shared IAM stack)
|
|
# from a single-env push — breaking the per-env dev/prod boundary. So we target one
|
|
# stack explicitly per env. (Infra CI still uses the reusable ci-typescript-cdk.)
|
|
#
|
|
# The shared IAM stack (open-swe-iam — owns BOTH envs' OIDC deploy roles) is
|
|
# intentionally NOT deployed here: it is a privileged, human-gated apply (T6), so a
|
|
# routine dev push can never alter prod's deploy role.
|
|
#
|
|
# OIDC subject alignment (must match the per-env trust in infra/lib/config.ts):
|
|
# - deploy-dev declares NO `environment:` → token sub = repo:…:ref:refs/heads/dev,
|
|
# which is exactly what githubdeploy-open-swe-infra-dev trusts.
|
|
# - deploy-prod declares `environment: prod` → token sub = repo:…:environment:prod,
|
|
# which githubdeploy-open-swe-infra-prod trusts AND which triggers the GitHub
|
|
# Environment's required-reviewer (manual approval) gate.
|
|
#
|
|
# Prerequisites (post-T6, when the roles exist):
|
|
# - repo variables AWS_DEPLOY_ROLE_INFRA_DEV / AWS_DEPLOY_ROLE_INFRA_PROD = the
|
|
# githubdeploy-open-swe-infra-<env> role ARNs (open-swe-iam CfnOutputs).
|
|
# - a GitHub Environment named "prod" with Adam as a required reviewer.
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches: [dev, main]
|
|
paths:
|
|
- "infra/**"
|
|
- ".github/workflows/cd-infra.yml"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
# one infra deploy per branch at a time; never cancel an in-flight deploy.
|
|
group: cd-infra-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
# CI-green precondition — re-run tsc + jest + synth on the pushed commit before
|
|
# any deploy. A failure here blocks the deploy jobs (needs: ci).
|
|
ci:
|
|
name: Infra CI (pre-deploy)
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
|
with:
|
|
node-version: "24"
|
|
working-directory: infra
|
|
cache-dependency-path: infra/package-lock.json
|
|
run-typecheck: true
|
|
run-tests: true
|
|
run-cdk-synth: true
|
|
|
|
deploy-dev:
|
|
name: Deploy open-swe-dev
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/dev' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_DEV }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (dev only)
|
|
working-directory: infra
|
|
run: npx cdk deploy OpenSweDevStack --require-approval never
|
|
- name: Stack outputs
|
|
run: |
|
|
aws cloudformation describe-stacks --stack-name open-swe-dev \
|
|
--query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table
|
|
|
|
deploy-prod:
|
|
name: Deploy open-swe-prod
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/main' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
# Manual-approval gate: the "prod" Environment requires a reviewer (Adam).
|
|
# Also makes the OIDC sub …:environment:prod (matches the prod role trust).
|
|
environment: prod
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_PROD }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (prod only)
|
|
working-directory: infra
|
|
run: npx cdk deploy OpenSweProdStack --require-approval never
|
|
- name: Stack outputs
|
|
run: |
|
|
aws cloudformation describe-stacks --stack-name open-swe-prod \
|
|
--query 'Stacks[0].Outputs[*].[OutputKey,OutputValue]' --output table
|