mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-09-30 06:33:13 +00:00
Phase 0 of proposal-system: complete project setup including: - CDK infrastructure (3 stacks: foundation, compute, frontend) - .NET 8 solution with Clean Architecture (Domain, Application, Infrastructure, Api) - EF Core data model (PostgreSQL) with all entities - Python Lambda placeholders (pdf-extract, pdf-generate, library-ingest) - React 19 web frontend scaffold (Vite + MUI) - React Native mobile placeholder - Shared TypeScript API contracts - GitHub Actions CI/CD (ci.yaml + deploy.yaml) - OIDC deploy role (githubdeploy-proposal-system) - Dependabot configuration - Cognito User Pool with Google OAuth, PKCE clients, groups
89 lines
2.5 KiB
YAML
89 lines
2.5 KiB
YAML
name: Deploy
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
jobs:
|
|
deploy:
|
|
name: Deploy to AWS
|
|
runs-on: ubuntu-latest
|
|
environment: production
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: 24
|
|
cache: npm
|
|
cache-dependency-path: infra/package-lock.json
|
|
|
|
- uses: actions/setup-dotnet@v4
|
|
with:
|
|
dotnet-version: '8.0.x'
|
|
|
|
- uses: actions/setup-python@v5
|
|
with:
|
|
python-version: '3.12'
|
|
|
|
- uses: aws-actions/configure-aws-credentials@v4
|
|
with:
|
|
role-to-assume: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|
|
aws-region: us-east-1
|
|
|
|
# Build .NET API
|
|
- name: Build API
|
|
working-directory: api
|
|
run: |
|
|
dotnet publish src/ProposalSystem.Api/ProposalSystem.Api.csproj \
|
|
--configuration Release \
|
|
--runtime linux-arm64 \
|
|
--self-contained false \
|
|
--output src/ProposalSystem.Api/bin/Release/net8.0/linux-arm64/publish
|
|
|
|
# Install Python dependencies for Lambdas
|
|
- name: Install PDF Extract deps
|
|
working-directory: lambdas/pdf-extract
|
|
run: pip install -r requirements.txt -t .
|
|
|
|
- name: Install PDF Generate deps
|
|
working-directory: lambdas/pdf-generate
|
|
run: pip install -r requirements.txt -t .
|
|
|
|
- name: Install Library Ingest deps
|
|
working-directory: lambdas/library-ingest
|
|
run: pip install -r requirements.txt -t .
|
|
|
|
# CDK Deploy
|
|
- name: CDK Deploy
|
|
working-directory: infra
|
|
run: |
|
|
npm ci
|
|
npx cdk deploy --all --require-approval never
|
|
|
|
# CloudFront Invalidation (after frontend deploy)
|
|
- name: Build Web Frontend
|
|
working-directory: web
|
|
run: |
|
|
npm ci
|
|
npm run build
|
|
|
|
- name: Deploy Web to S3
|
|
run: |
|
|
BUCKET=$(aws cloudformation describe-stacks \
|
|
--stack-name proposal-system-frontend \
|
|
--query "Stacks[0].Outputs[?OutputKey=='SiteBucketName'].OutputValue" \
|
|
--output text)
|
|
aws s3 sync web/dist "s3://$BUCKET" --delete
|
|
|
|
- name: Invalidate CloudFront
|
|
run: |
|
|
DIST_ID=$(aws cloudformation describe-stacks \
|
|
--stack-name proposal-system-frontend \
|
|
--query "Stacks[0].Outputs[?OutputKey=='DistributionId'].OutputValue" \
|
|
--output text)
|
|
aws cloudfront create-invalidation --distribution-id "$DIST_ID" --paths "/*"
|