mirror of
https://github.com/Sea-Haven-Industries/open-swe.git
synced 2026-09-30 23:13:15 +00:00
* Align workflows with Sea Haven CI/CD handbook Bring the workflow suite in line with the handbook: bump actions/checkout to v7 (Node 24 runtime, already standardized), kebab-case the two snake_case workflow filenames, and add the org-standard Labeler caller and Dependency Review gate so vulnerable or disallowed-license deps and unlabeled PRs are caught automatically. File renames only — job/check display names are unchanged, so the promotion gate's REQUIRED_CHECKS and branch-protection required checks are unaffected. Refs: INFRA-115 * Drop Agent prefix from CI workflow + job names The handbook names workflows for what they do (CI, Deploy, Labeler), not the component they run, matching .github and afterhours-shift-manager. Rename the suite to CI and its jobs to Lint / Format check / Unit tests, and keep the promotion gate's REQUIRED_CHECKS in sync. Refs: INFRA-115 --------- Co-authored-by: seahaven-openswe[bot] <296972425+seahaven-openswe[bot]@users.noreply.github.com>
124 lines
4.7 KiB
YAML
124 lines
4.7 KiB
YAML
name: Infra CD
|
|
|
|
# Path-filtered CDK deploy for /infra, per env, OIDC-only (no static keys).
|
|
#
|
|
# push to dev → CI (tsc+jest+synth) → deploy OpenSweDevStack (AUTO, CI-green-gated)
|
|
# push to main → CI → deploy OpenSweProdStack (manual approval: env "prod")
|
|
#
|
|
# Why this is NOT the reusable cd-cdk.yaml: that workflow runs `cdk deploy --all`,
|
|
# which would deploy ALL THREE stacks (incl. the OTHER env + the shared IAM stack)
|
|
# from a single-env push — breaking the per-env dev/prod boundary. So we target one
|
|
# stack explicitly per env. (Infra CI still uses the reusable ci-typescript-cdk.)
|
|
#
|
|
# The shared IAM stack (open-swe-iam — owns BOTH envs' OIDC deploy roles) is
|
|
# intentionally NOT deployed here: it is a privileged, human-gated apply (T6), so a
|
|
# routine dev push can never alter prod's deploy role.
|
|
#
|
|
# OIDC subject alignment (must match the per-env trust in infra/lib/config.ts):
|
|
# - deploy-dev declares NO `environment:` → token sub = repo:…:ref:refs/heads/dev,
|
|
# which is exactly what githubdeploy-open-swe-infra-dev trusts.
|
|
# - deploy-prod declares `environment: prod` → token sub = repo:…:environment:prod,
|
|
# which githubdeploy-open-swe-infra-prod trusts AND which triggers the GitHub
|
|
# Environment's required-reviewer (manual approval) gate.
|
|
#
|
|
# Prerequisites (post-T6, when the roles exist):
|
|
# - repo variables AWS_DEPLOY_ROLE_INFRA_DEV / AWS_DEPLOY_ROLE_INFRA_PROD = the
|
|
# githubdeploy-open-swe-infra-<env> role ARNs (open-swe-iam CfnOutputs).
|
|
# - a GitHub Environment named "prod" with Adam as a required reviewer.
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
branches: [dev, main]
|
|
paths:
|
|
- "infra/**"
|
|
- ".github/workflows/cd-infra.yml"
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
# one infra deploy per branch at a time; never cancel an in-flight deploy.
|
|
group: cd-infra-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
# CI-green precondition — re-run tsc + jest + synth on the pushed commit before
|
|
# any deploy. A failure here blocks the deploy jobs (needs: ci).
|
|
ci:
|
|
name: Infra CI (pre-deploy)
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
|
|
with:
|
|
node-version: "24"
|
|
working-directory: infra
|
|
cache-dependency-path: infra/package-lock.json
|
|
run-typecheck: true
|
|
run-tests: true
|
|
run-cdk-synth: true
|
|
|
|
deploy-dev:
|
|
name: Deploy open-swe-dev
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/dev' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_DEV }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (dev only)
|
|
working-directory: infra
|
|
# --outputs-file lets us print the stack outputs from CDK's own result
|
|
# (the deploy role intentionally lacks cloudformation:DescribeStacks; CDK
|
|
# gets outputs via the bootstrap cfn-exec role it assumes, so no extra grant).
|
|
run: npx cdk deploy OpenSweDevStack --require-approval never --outputs-file cdk-outputs.json
|
|
- name: Stack outputs
|
|
working-directory: infra
|
|
run: cat cdk-outputs.json
|
|
|
|
deploy-prod:
|
|
name: Deploy open-swe-prod
|
|
needs: ci
|
|
if: ${{ github.ref == 'refs/heads/main' }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
# Manual-approval gate: the "prod" Environment requires a reviewer (Adam).
|
|
# Also makes the OIDC sub …:environment:prod (matches the prod role trust).
|
|
environment: prod
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
- name: Install deps
|
|
working-directory: infra
|
|
run: npm ci
|
|
- uses: aws-actions/configure-aws-credentials@v6
|
|
with:
|
|
role-to-assume: ${{ vars.AWS_DEPLOY_ROLE_INFRA_PROD }}
|
|
aws-region: us-east-1
|
|
- name: CDK deploy (prod only)
|
|
working-directory: infra
|
|
# See deploy-dev: --outputs-file avoids needing cloudformation:DescribeStacks.
|
|
run: npx cdk deploy OpenSweProdStack --require-approval never --outputs-file cdk-outputs.json
|
|
- name: Stack outputs
|
|
working-directory: infra
|
|
run: cat cdk-outputs.json
|