proposal-system/scripts/post-deploy.sh
Adam Moussa 80e36bfb9a Fix Phase 3 audit findings: polish, operational maturity, and remaining FIX items
Addresses 29 FIX-severity findings and accessibility/code-quality NITs
from the 2026-05-20 audit. Key changes:

- Add confirmation dialogs for Mark as Sent and Create Revision (FIX-17)
- Restrict S3 CORS from wildcard to specific origins (FIX-38)
- Add API Gateway throttling at 100 rps / 50 burst (FIX-39)
- Separate vendor upload from SQS extraction trigger (FIX-04/05)
- Copy TotalBidAmount on proposal revision (FIX-11)
- Add CI paths-ignore and concurrency group (FIX-47)
- Add post-deploy health check (FIX-46)
- Fix N+1 query, Guid.Empty FK, pagination bounds, role sync (FIX-01/02/07/09)
- Fix dashboard OOM, status transitions, audit error handling (FIX-03/06/12)
- Fix frontend date filters, error display, currency formatting (FIX-14/16/18-23)
- Remove AOSS dashboard public access, skip empty AI suggestions (FIX-41/45)
- Add aria-labels, document.title management, deduplicate constants
- Restrict CORS localhost to development, log invalid API key attempts

[skip deploy]
2026-05-20 19:35:13 -04:00

34 lines
1.1 KiB
Bash
Executable file

#!/usr/bin/env bash
set -euo pipefail
cd web
npm ci
npm run build
cd ..
BUCKET=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
--output text)
aws s3 sync web/dist "s3://$BUCKET" --delete
DIST_ID=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
--output text)
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"
# Health check: verify API is reachable
API_URL=$(aws cloudformation describe-stacks \
--stack-name proposal-system-compute \
--query "Stacks[0].Outputs[?OutputKey=='ApiEndpoint'].OutputValue" \
--output text)
echo "Running post-deploy health check..."
HTTP_STATUS=$(curl -s -o /dev/null -w "%{http_code}" "${API_URL}/api/health" --max-time 10 || true)
if [ "$HTTP_STATUS" -eq 200 ]; then
echo "Health check passed (HTTP $HTTP_STATUS)"
else
echo "WARNING: Health check returned HTTP $HTTP_STATUS" >&2
exit 1
fi