fix(cd): keep SHA-tagged API images for rollback

This commit is contained in:
Adam Moussa 2026-09-26 16:23:42 -04:00
parent 15e80d56c0
commit f0a200f6e9
No known key found for this signature in database
2 changed files with 7 additions and 4 deletions

View file

@ -32,6 +32,8 @@ def test_no_hcp_iam_and_no_prod():
assert "ignore_changes = [task_definition, desired_count]" in ecs
assert 'path = "/api/health"' in ecs
assert "public.ecr.aws/docker/library/node:24-alpine" in ecs
assert 'tagStatus = "untagged"' in ecs
assert 'tagStatus = "any"' not in ecs
cloudfront = (tf_dir / "cloudfront.tf").read_text()
assert "cloudfront_default_certificate = true" in cloudfront
assert "aliases" not in cloudfront

View file

@ -19,11 +19,12 @@ resource "aws_ecr_lifecycle_policy" "api" {
rules = [
{
rulePriority = 1
description = "Keep the last 20 images"
description = "Expire untagged images. SHA tags stay so registered task revisions can roll back."
selection = {
tagStatus = "any"
countType = "imageCountMoreThan"
countNumber = 20
tagStatus = "untagged"
countType = "sinceImagePushed"
countUnit = "days"
countNumber = 14
}
action = {
type = "expire"