proposal-system/.github/workflows/deploy.yaml
Adam Moussa 0b055b3ad9 Initial scaffold: monorepo structure, CDK stacks, CI/CD, domain model
Phase 0 of proposal-system: complete project setup including:
- CDK infrastructure (3 stacks: foundation, compute, frontend)
- .NET 8 solution with Clean Architecture (Domain, Application, Infrastructure, Api)
- EF Core data model (PostgreSQL) with all entities
- Python Lambda placeholders (pdf-extract, pdf-generate, library-ingest)
- React 19 web frontend scaffold (Vite + MUI)
- React Native mobile placeholder
- Shared TypeScript API contracts
- GitHub Actions CI/CD (ci.yaml + deploy.yaml)
- OIDC deploy role (githubdeploy-proposal-system)
- Dependabot configuration
- Cognito User Pool with Google OAuth, PKCE clients, groups
2026-05-16 18:40:46 -04:00

89 lines
2.5 KiB
YAML

name: Deploy
on:
push:
branches: [main]
permissions:
id-token: write
contents: read
jobs:
deploy:
name: Deploy to AWS
runs-on: ubuntu-latest
environment: production
steps:
- uses: actions/checkout@v6
- uses: actions/setup-node@v4
with:
node-version: 24
cache: npm
cache-dependency-path: infra/package-lock.json
- uses: actions/setup-dotnet@v4
with:
dotnet-version: '8.0.x'
- uses: actions/setup-python@v5
with:
python-version: '3.12'
- uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
aws-region: us-east-1
# Build .NET API
- name: Build API
working-directory: api
run: |
dotnet publish src/ProposalSystem.Api/ProposalSystem.Api.csproj \
--configuration Release \
--runtime linux-arm64 \
--self-contained false \
--output src/ProposalSystem.Api/bin/Release/net8.0/linux-arm64/publish
# Install Python dependencies for Lambdas
- name: Install PDF Extract deps
working-directory: lambdas/pdf-extract
run: pip install -r requirements.txt -t .
- name: Install PDF Generate deps
working-directory: lambdas/pdf-generate
run: pip install -r requirements.txt -t .
- name: Install Library Ingest deps
working-directory: lambdas/library-ingest
run: pip install -r requirements.txt -t .
# CDK Deploy
- name: CDK Deploy
working-directory: infra
run: |
npm ci
npx cdk deploy --all --require-approval never
# CloudFront Invalidation (after frontend deploy)
- name: Build Web Frontend
working-directory: web
run: |
npm ci
npm run build
- name: Deploy Web to S3
run: |
BUCKET=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
--output text)
aws s3 sync web/dist "s3://$BUCKET" --delete
- name: Invalidate CloudFront
run: |
DIST_ID=$(aws cloudformation describe-stacks \
--stack-name proposal-system-frontend \
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
--output text)
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"