Refactor workflows to thin wrappers calling org reusable workflows

CI jobs now call ci-dotnet, ci-typescript-cdk, and ci-python-sam
from the org repo. Deploy calls cd-cdk with post-deploy script
for web build/S3/CloudFront. Mobile deploy calls cd-mobile-ios.
Adds deploy concurrency groups to both deploy workflows.
This commit is contained in:
Adam Moussa 2026-05-18 15:11:57 -04:00
parent e1534d50ab
commit af1720b6c3
4 changed files with 72 additions and 196 deletions

View file

@ -10,91 +10,43 @@ permissions:
jobs: jobs:
dotnet: dotnet:
name: .NET Build & Test name: .NET Build & Test
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/ci-dotnet.yaml@main
defaults:
run:
working-directory: api
steps:
- uses: actions/checkout@v6
- uses: actions/setup-dotnet@v5
with: with:
dotnet-version: '8.0.x' working-directory: api
solution: ProposalSystem.sln
- run: dotnet restore ProposalSystem.sln
- run: dotnet build ProposalSystem.sln --no-restore --configuration Release
- run: dotnet test ProposalSystem.sln --no-build --configuration Release
web: web:
name: Web Frontend Check name: Web Frontend Check
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
defaults:
run:
working-directory: web
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with: with:
node-version: 24 working-directory: web
cache: npm
cache-dependency-path: web/package-lock.json cache-dependency-path: web/package-lock.json
run-cdk-synth: false
- run: npm ci run-conventions-check: false
- run: npx tsc --noEmit
python: python:
name: Python Lint name: Python Lint
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/ci-python-sam.yaml@main
steps:
- uses: actions/checkout@v6
- uses: actions/setup-python@v5
with: with:
python-version: '3.12' source-dirs: "lambdas/"
run-sam-validate: false
- run: pip install ruff run-conventions-check: false
- run: ruff check lambdas/
- run: ruff format --check lambdas/
mobile: mobile:
name: Mobile Typecheck name: Mobile Typecheck
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
defaults:
run:
working-directory: mobile
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with: with:
node-version: 24 working-directory: mobile
cache: npm
cache-dependency-path: mobile/package-lock.json cache-dependency-path: mobile/package-lock.json
run-cdk-synth: false
- run: npm ci run-conventions-check: false
- run: npx tsc --noEmit
infra: infra:
name: CDK Synth name: CDK Synth
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/ci-typescript-cdk.yaml@main
steps:
- uses: actions/checkout@v6
- uses: actions/setup-dotnet@v4
with: with:
dotnet-version: '8.0.x' working-directory: infra
- name: Publish .NET API (required for CDK asset path)
run: dotnet publish api/src/ProposalSystem.Api/ProposalSystem.Api.csproj --configuration Release --runtime linux-arm64 --self-contained
- uses: actions/setup-node@v6
with:
node-version: 24
cache: npm
cache-dependency-path: infra/package-lock.json cache-dependency-path: infra/package-lock.json
dotnet-version: "8.0.x"
- run: npm ci dotnet-publish-project: api/src/ProposalSystem.Api/ProposalSystem.Api.csproj
working-directory: infra run-typecheck: false
- run: npx cdk synth
working-directory: infra

View file

@ -8,48 +8,20 @@ name: Deploy Mobile (iOS)
on: on:
workflow_dispatch: workflow_dispatch:
permissions: concurrency:
id-token: write group: deploy-mobile
contents: read cancel-in-progress: false
jobs: jobs:
deploy-ios: deploy-ios:
name: Build & Upload to TestFlight name: Build & Upload to TestFlight
runs-on: macos-latest uses: Sea-Haven-Industries/.github/.github/workflows/cd-mobile-ios.yaml@main
defaults: with:
run:
working-directory: mobile working-directory: mobile
timeout-minutes: 45
steps:
- uses: actions/checkout@v6
- uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
aws-region: us-east-1
- uses: actions/setup-node@v6
with:
node-version: 24
cache: npm
cache-dependency-path: mobile/package-lock.json cache-dependency-path: mobile/package-lock.json
secrets:
- uses: ruby/setup-ruby@v1 deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
with: match-password: ${{ secrets.MATCH_PASSWORD }}
ruby-version: "3.3" asc-key-id: ${{ secrets.ASC_KEY_ID }}
bundler-cache: true asc-issuer-id: ${{ secrets.ASC_ISSUER_ID }}
working-directory: mobile asc-key-content: ${{ secrets.ASC_KEY_CONTENT }}
- name: Install JS dependencies
run: npm ci
- name: Install CocoaPods
run: bundle exec pod install --project-directory=ios
- name: Build and upload to TestFlight
run: bundle exec fastlane ios beta
env:
MATCH_PASSWORD: ${{ secrets.MATCH_PASSWORD }}
ASC_KEY_ID: ${{ secrets.ASC_KEY_ID }}
ASC_ISSUER_ID: ${{ secrets.ASC_ISSUER_ID }}
ASC_KEY_CONTENT: ${{ secrets.ASC_KEY_CONTENT }}

View file

@ -4,86 +4,19 @@ on:
push: push:
branches: [main] branches: [main]
permissions: concurrency:
id-token: write group: deploy-backend
contents: read cancel-in-progress: false
jobs: jobs:
deploy: deploy:
name: Deploy to AWS name: Deploy to AWS
runs-on: ubuntu-latest uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
environment: production
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v6
with: with:
node-version: 24 cdk-dir: infra
cache: npm dotnet-version: "8.0.x"
cache-dependency-path: infra/package-lock.json dotnet-publish-project: api/src/ProposalSystem.Api/ProposalSystem.Api.csproj
python-version: "3.12"
- uses: actions/setup-dotnet@v5 post-deploy-script: scripts/post-deploy.sh
with: secrets:
dotnet-version: '8.0.x' deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
aws-region: us-east-1
# Build .NET API
- name: Build API
working-directory: api
run: |
dotnet publish src/ProposalSystem.Api/ProposalSystem.Api.csproj \
--configuration Release \
--runtime linux-arm64 \
--self-contained false \
--output src/ProposalSystem.Api/bin/Release/net8.0/linux-arm64/publish
# Install Python dependencies for Lambdas
- name: Install PDF Extract deps
working-directory: lambdas/pdf-extract
run: pip install -r requirements.txt -t .
- name: Install PDF Generate deps
working-directory: lambdas/pdf-generate
run: pip install -r requirements.txt -t .
- name: Install Library Ingest deps
working-directory: lambdas/library-ingest
run: pip install -r requirements.txt -t .
# CDK Deploy
- name: CDK Deploy
working-directory: infra
run: |
npm ci
npx cdk deploy --all --require-approval never
# CloudFront Invalidation (after frontend deploy)
- name: Build Web Frontend
working-directory: web
run: |
npm ci
npm run build
- name: Deploy Web to S3
run: |
BUCKET=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
--output text)
aws s3 sync web/dist "s3://$BUCKET" --delete
- name: Invalidate CloudFront
run: |
DIST_ID=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
--output text)
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"

19
scripts/post-deploy.sh Executable file
View file

@ -0,0 +1,19 @@
#!/usr/bin/env bash
set -euo pipefail
cd web
npm ci
npm run build
cd ..
BUCKET=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
--output text)
aws s3 sync web/dist "s3://$BUCKET" --delete
DIST_ID=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
--output text)
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"