fix(cd): keep SHA-tagged API images for rollback

This commit is contained in:
Adam Moussa 2026-09-26 16:23:42 -04:00
parent 15e80d56c0
commit f0a200f6e9
No known key found for this signature in database
2 changed files with 7 additions and 4 deletions

View file

@ -32,6 +32,8 @@ def test_no_hcp_iam_and_no_prod():
assert "ignore_changes = [task_definition, desired_count]" in ecs assert "ignore_changes = [task_definition, desired_count]" in ecs
assert 'path = "/api/health"' in ecs assert 'path = "/api/health"' in ecs
assert "public.ecr.aws/docker/library/node:24-alpine" in ecs assert "public.ecr.aws/docker/library/node:24-alpine" in ecs
assert 'tagStatus = "untagged"' in ecs
assert 'tagStatus = "any"' not in ecs
cloudfront = (tf_dir / "cloudfront.tf").read_text() cloudfront = (tf_dir / "cloudfront.tf").read_text()
assert "cloudfront_default_certificate = true" in cloudfront assert "cloudfront_default_certificate = true" in cloudfront
assert "aliases" not in cloudfront assert "aliases" not in cloudfront

View file

@ -19,11 +19,12 @@ resource "aws_ecr_lifecycle_policy" "api" {
rules = [ rules = [
{ {
rulePriority = 1 rulePriority = 1
description = "Keep the last 20 images" description = "Expire untagged images. SHA tags stay so registered task revisions can roll back."
selection = { selection = {
tagStatus = "any" tagStatus = "untagged"
countType = "imageCountMoreThan" countType = "sinceImagePushed"
countNumber = 20 countUnit = "days"
countNumber = 14
} }
action = { action = {
type = "expire" type = "expire"