mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-09-30 08:03:20 +00:00
fix(cd): name the missing deploy prerequisites
This commit is contained in:
parent
0a16df1cfe
commit
fe4bbc95fb
4 changed files with 51 additions and 3 deletions
22
.github/workflows/deploy-api.yaml
vendored
22
.github/workflows/deploy-api.yaml
vendored
|
|
@ -131,6 +131,14 @@ jobs:
|
|||
echo "sha=${sha}" >> "${GITHUB_OUTPUT}"
|
||||
echo "Building ${sha}"
|
||||
|
||||
- name: Require deploy role
|
||||
run: |
|
||||
set -euo pipefail
|
||||
if [ -z "${DEPLOY_ROLE_ARN}" ]; then
|
||||
echo "DEPLOY_ROLE_ARN is empty. Create GitHub Environment dev and set it after the seahaven-ap-dev apply, then re-run." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Configure AWS credentials using OIDC
|
||||
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
||||
with:
|
||||
|
|
@ -143,7 +151,19 @@ jobs:
|
|||
run: |
|
||||
set -euo pipefail
|
||||
get_param() {
|
||||
aws ssm get-parameter --name "$1" --query Parameter.Value --output text
|
||||
local name="$1" err value
|
||||
err="$(mktemp)"
|
||||
if ! value="$(aws ssm get-parameter --name "${name}" --query Parameter.Value --output text 2>"${err}")"; then
|
||||
if grep -q ParameterNotFound "${err}"; then
|
||||
echo "SSM parameter ${name} does not exist yet. Apply the seahaven-ap-dev workspace, then re-run this workflow." >&2
|
||||
else
|
||||
cat "${err}" >&2
|
||||
fi
|
||||
rm -f "${err}"
|
||||
exit 1
|
||||
fi
|
||||
rm -f "${err}"
|
||||
printf '%s\n' "${value}"
|
||||
}
|
||||
CLUSTER=$(get_param /seahaven-ap/deploy/cluster)
|
||||
SERVICE=$(get_param /seahaven-ap/deploy/service)
|
||||
|
|
|
|||
27
.github/workflows/deploy-web.yaml
vendored
27
.github/workflows/deploy-web.yaml
vendored
|
|
@ -124,6 +124,14 @@ jobs:
|
|||
echo "Deploying ${sha}"
|
||||
test -f placeholder/index.html
|
||||
|
||||
- name: Require deploy role
|
||||
run: |
|
||||
set -euo pipefail
|
||||
if [ -z "${DEPLOY_ROLE_ARN}" ]; then
|
||||
echo "DEPLOY_ROLE_ARN is empty. Create GitHub Environment dev and set it after the seahaven-ap-dev apply, then re-run." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Configure AWS credentials using OIDC
|
||||
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
||||
with:
|
||||
|
|
@ -135,8 +143,23 @@ jobs:
|
|||
id: deploy
|
||||
run: |
|
||||
set -euo pipefail
|
||||
BUCKET=$(aws ssm get-parameter --name /seahaven-ap/deploy/bucket --query Parameter.Value --output text)
|
||||
DIST_ID=$(aws ssm get-parameter --name /seahaven-ap/deploy/distribution-id --query Parameter.Value --output text)
|
||||
get_param() {
|
||||
local name="$1" err value
|
||||
err="$(mktemp)"
|
||||
if ! value="$(aws ssm get-parameter --name "${name}" --query Parameter.Value --output text 2>"${err}")"; then
|
||||
if grep -q ParameterNotFound "${err}"; then
|
||||
echo "SSM parameter ${name} does not exist yet. Apply the seahaven-ap-dev workspace, then re-run this workflow." >&2
|
||||
else
|
||||
cat "${err}" >&2
|
||||
fi
|
||||
rm -f "${err}"
|
||||
exit 1
|
||||
fi
|
||||
rm -f "${err}"
|
||||
printf '%s\n' "${value}"
|
||||
}
|
||||
BUCKET=$(get_param /seahaven-ap/deploy/bucket)
|
||||
DIST_ID=$(get_param /seahaven-ap/deploy/distribution-id)
|
||||
DOMAIN=$(aws cloudfront get-distribution --id "${DIST_ID}" --query Distribution.DomainName --output text)
|
||||
{
|
||||
echo "bucket=${BUCKET}"
|
||||
|
|
|
|||
|
|
@ -60,6 +60,8 @@ HCP Terraform workspace `seahaven-ap-dev` (project `seahaven-dev`) uses working
|
|||
|
||||
The first apply creates secret `seahaven-ap/google-oidc` with `client_id` and `client_secret` set to `replace-me`. Replace both values in Secrets Manager, then re-run the HCP apply. A `terraform/**` change on `main` starts that apply. The Google IdP is not registered while the placeholder is still current.
|
||||
|
||||
The merge that adds these workflows can start Deploy Web and Deploy API before that apply has written `/seahaven-ap/deploy/*` and before GitHub Environment `dev` has `DEPLOY_ROLE_ARN`. Those runs fail on purpose until both exist. Re-run them after the apply.
|
||||
|
||||
- `.github/workflows/deploy-web.yaml` syncs `placeholder/` to the web bucket. It does not run `vite build`.
|
||||
- `.github/workflows/deploy-api.yaml` builds the API image with `GIT_SHA`, registers the task definition from `/seahaven-ap/deploy/task-environment`, migrates, and checks `GET /api/health`.
|
||||
|
||||
|
|
|
|||
|
|
@ -54,6 +54,7 @@ def test_no_hcp_iam_and_no_prod():
|
|||
assert 'local.google_oidc_client_secret != "replace-me"' in cognito
|
||||
readme = (ROOT / "README.md").read_text()
|
||||
assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme
|
||||
assert "Those runs fail on purpose until both exist." in readme
|
||||
secrets = (tf_dir / "secrets.tf").read_text()
|
||||
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
|
||||
assert "ignore_changes = [secret_string]" in secrets
|
||||
|
|
@ -74,6 +75,8 @@ def test_deploy_workflows_are_dev_only():
|
|||
assert "environment:prod" not in text
|
||||
assert "cancel-in-progress: false" in text
|
||||
assert "environment: ${{ needs.target.outputs.environment }}" in text
|
||||
assert "DEPLOY_ROLE_ARN is empty" in text
|
||||
assert "does not exist yet. Apply the seahaven-ap-dev workspace" in text
|
||||
web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text()
|
||||
assert "vite build" not in web
|
||||
assert "placeholder/" in web
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue