diff --git a/.github/workflows/deploy-api.yaml b/.github/workflows/deploy-api.yaml index dcff899..6b01871 100644 --- a/.github/workflows/deploy-api.yaml +++ b/.github/workflows/deploy-api.yaml @@ -5,7 +5,9 @@ name: Deploy API # and ignores container_definitions / task_definition. # # push to main -> GitHub Environment dev, at github.sha -# workflow_dispatch -> GitHub Environment dev at a chosen ref +# workflow_dispatch -> GitHub Environment dev. The workflow file must be main. +# inputs.ref is only the image source. Deploy scripts stay +# on github.sha, which is the trusted workflow commit. # # Cluster, service, ECR, and task env come from SSM after assuming the # Environment's DEPLOY_ROLE_ARN. Terraform owns /seahaven-ap/deploy/task-environment; @@ -68,6 +70,10 @@ jobs: ref="${GITHUB_SHA_IN}" ;; workflow_dispatch) + if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then + echo "workflow_dispatch deploys only run from main" >&2 + exit 1 + fi environment="${INPUT_ENVIRONMENT:-dev}" if [ "${environment}" != "dev" ]; then echo "only GitHub Environment dev is allowed" >&2 @@ -102,13 +108,23 @@ jobs: AWS_REGION: us-east-1 DEPLOY_ROLE_ARN: ${{ vars.DEPLOY_ROLE_ARN }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Checkout trusted workflow + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + ref: ${{ github.sha }} + persist-credentials: false + path: ci + + - name: Checkout image source + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: ref: ${{ needs.target.outputs.ref }} persist-credentials: false + path: src - name: Resolve commit id: commit + working-directory: src run: | set -euo pipefail sha="$(git rev-parse HEAD)" @@ -153,6 +169,7 @@ jobs: ECR: ${{ steps.deploy.outputs.ecr }} GIT_SHA: ${{ steps.commit.outputs.sha }} ENVIRONMENT: ${{ needs.target.outputs.environment }} + working-directory: src run: | set -euo pipefail docker build \ @@ -192,7 +209,7 @@ jobs: --task-definition "${FAMILY}" \ --query taskDefinition \ --output json \ - | python3 scripts/patch-ecs-task-def.py > /tmp/task-def.json + | python3 "${GITHUB_WORKSPACE}/ci/scripts/patch-ecs-task-def.py" > /tmp/task-def.json REV="$(aws ecs register-task-definition --cli-input-json file:///tmp/task-def.json --query taskDefinition.revision --output text)" NET="$(aws ecs describe-services --cluster "${CLUSTER}" --services "${SERVICE}" \ --query 'services[0].networkConfiguration.awsvpcConfiguration' --output json)" @@ -225,4 +242,4 @@ jobs: env: SITE_URL: ${{ steps.deploy.outputs.site_url }} EXPECTED_SHA: ${{ steps.commit.outputs.sha }} - run: bash scripts/verify-api-health.sh + run: bash "${GITHUB_WORKSPACE}/ci/scripts/verify-api-health.sh" diff --git a/.github/workflows/deploy-web.yaml b/.github/workflows/deploy-web.yaml index 36cca87..3e2ea96 100644 --- a/.github/workflows/deploy-web.yaml +++ b/.github/workflows/deploy-web.yaml @@ -5,7 +5,9 @@ name: Deploy Web # distribution and never touches content. Do not run a SPA production build. # # push to main -> GitHub Environment dev, at github.sha -# workflow_dispatch -> GitHub Environment dev at a chosen ref +# workflow_dispatch -> GitHub Environment dev. The workflow file must be main. +# inputs.ref selects the placeholder tree to publish. +# Job steps are the workflow file, not scripts from that ref. # # Nothing here creates an HCP run. Prod is AP-12. @@ -70,6 +72,10 @@ jobs: ref="${GITHUB_SHA_IN}" ;; workflow_dispatch) + if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then + echo "workflow_dispatch deploys only run from main" >&2 + exit 1 + fi environment="${INPUT_ENVIRONMENT:-dev}" if [ "${environment}" != "dev" ]; then echo "only GitHub Environment dev is allowed" >&2