mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 19:43:15 +00:00
cd-infra reported failure on every successful deploy: the 'Stack outputs' step ran 'aws cloudformation describe-stacks' with the githubdeploy-open-swe-infra-<env> role, which intentionally lacks cloudformation:DescribeStacks. The cdk deploy itself succeeds (it reads outputs via the bootstrap cfn-exec role it assumes). Switch to 'cdk deploy --outputs-file cdk-outputs.json' + cat — no extra IAM grant, and the job goes green on actual deploy success instead of masking real failures behind a red run.
124 lines
4.7 KiB
YAML
124 lines
4.7 KiB
YAML
name: Infra CD
|
|
|
|
# Path-filtered CDK deploy for /infra, per env, OIDC-only (no static keys).
|
|
#
|
|
# push to dev → CI (tsc+jest+synth) → deploy OpenSweDevStack (AUTO, CI-green-gated)
|
|
# push to main → CI → deploy OpenSweProdStack (manual approval: env "prod")
|
|
#
|
|
# Why this is NOT the reusable cd-cdk.yaml: that workflow runs `cdk deploy --all`,
|
|
# which would deploy ALL THREE stacks (incl. the OTHER env + the shared IAM stack)
|
|
# from a single-env push — breaking the per-env dev/prod boundary. So we target one
|
|
# stack explicitly per env. (Infra CI still uses the reusable ci-typescript-cdk.)
|
|
#
|
|
# The shared IAM stack (open-swe-iam — owns BOTH envs' OIDC deploy roles) is
|
|
# intentionally NOT deployed here: it is a privileged, human-gated apply (T6), so a
|
|
# routine dev push can never alter prod's deploy role.
|
|
#
|
|
# OIDC subject alignment (must match the per-env trust in infra/lib/config.ts):
|
|
# - deploy-dev declares NO `environment:` → token sub = repo:…:ref:refs/heads/dev,
|
|
# which is exactly what githubdeploy-open-swe-infra-dev trusts.
|
|
# - deploy-prod declares `environment: prod` → token sub = repo:…:environment:prod,
|
|
# which githubdeploy-open-swe-infra-prod trusts AND which triggers the GitHub
|
|
# Environment's required-reviewer (manual approval) gate.
|
|
#
|
|
# Prerequisites (post-T6, when the roles exist):
|
|
# - repo variables AWS_DEPLOY_ROLE_INFRA_DEV / AWS_DEPLOY_ROLE_INFRA_PROD = the
|
|
# githubdeploy-open-swe-infra-<env> role ARNs (open-swe-iam CfnOutputs).
|
|
# - a GitHub Environment named "prod" with Adam as a required reviewer.
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches: [dev, main]
|
|
paths:
|
|
- "infra/**"
|
|
- ".github/workflows/cd-infra.yml"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
# one infra deploy per branch at a time; never cancel an in-flight deploy.
|
|
group: cd-infra-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
# CI-green precondition — re-run tsc + jest + synth on the pushed commit before
|
|
# any deploy. A failure here blocks the deploy jobs (needs: ci).
|
|
ci:
|
|
name: Infra CI (pre-deploy)
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
|
with:
|
|
node-version: "24"
|
|
working-directory: infra
|
|
cache-dependency-path: infra/package-lock.json
|
|
run-typecheck: true
|
|
run-tests: true
|
|
run-cdk-synth: true
|
|
|
|
deploy-dev:
|
|
name: Deploy open-swe-dev
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/dev' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_DEV }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (dev only)
|
|
working-directory: infra
|
|
# --outputs-file lets us print the stack outputs from CDK's own result
|
|
# (the deploy role intentionally lacks cloudformation:DescribeStacks; CDK
|
|
# gets outputs via the bootstrap cfn-exec role it assumes, so no extra grant).
|
|
run: npx cdk deploy OpenSweDevStack --require-approval never --outputs-file cdk-outputs.json
|
|
- name: Stack outputs
|
|
working-directory: infra
|
|
run: cat cdk-outputs.json
|
|
|
|
deploy-prod:
|
|
name: Deploy open-swe-prod
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/main' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
# Manual-approval gate: the "prod" Environment requires a reviewer (Adam).
|
|
# Also makes the OIDC sub …:environment:prod (matches the prod role trust).
|
|
environment: prod
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_PROD }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (prod only)
|
|
working-directory: infra
|
|
# See deploy-dev: --outputs-file avoids needing cloudformation:DescribeStacks.
|
|
run: npx cdk deploy OpenSweProdStack --require-approval never --outputs-file cdk-outputs.json
|
|
- name: Stack outputs
|
|
working-directory: infra
|
|
run: cat cdk-outputs.json
|