fix(cd): name the missing deploy prerequisites

This commit is contained in:
Adam Moussa 2026-09-26 16:49:44 -04:00
parent 0a16df1cfe
commit fe4bbc95fb
No known key found for this signature in database
4 changed files with 51 additions and 3 deletions

View file

@ -131,6 +131,14 @@ jobs:
echo "sha=${sha}" >> "${GITHUB_OUTPUT}"
echo "Building ${sha}"
- name: Require deploy role
run: |
set -euo pipefail
if [ -z "${DEPLOY_ROLE_ARN}" ]; then
echo "DEPLOY_ROLE_ARN is empty. Create GitHub Environment dev and set it after the seahaven-ap-dev apply, then re-run." >&2
exit 1
fi
- name: Configure AWS credentials using OIDC
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
@ -143,7 +151,19 @@ jobs:
run: |
set -euo pipefail
get_param() {
aws ssm get-parameter --name "$1" --query Parameter.Value --output text
local name="$1" err value
err="$(mktemp)"
if ! value="$(aws ssm get-parameter --name "${name}" --query Parameter.Value --output text 2>"${err}")"; then
if grep -q ParameterNotFound "${err}"; then
echo "SSM parameter ${name} does not exist yet. Apply the seahaven-ap-dev workspace, then re-run this workflow." >&2
else
cat "${err}" >&2
fi
rm -f "${err}"
exit 1
fi
rm -f "${err}"
printf '%s\n' "${value}"
}
CLUSTER=$(get_param /seahaven-ap/deploy/cluster)
SERVICE=$(get_param /seahaven-ap/deploy/service)

View file

@ -124,6 +124,14 @@ jobs:
echo "Deploying ${sha}"
test -f placeholder/index.html
- name: Require deploy role
run: |
set -euo pipefail
if [ -z "${DEPLOY_ROLE_ARN}" ]; then
echo "DEPLOY_ROLE_ARN is empty. Create GitHub Environment dev and set it after the seahaven-ap-dev apply, then re-run." >&2
exit 1
fi
- name: Configure AWS credentials using OIDC
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
with:
@ -135,8 +143,23 @@ jobs:
id: deploy
run: |
set -euo pipefail
BUCKET=$(aws ssm get-parameter --name /seahaven-ap/deploy/bucket --query Parameter.Value --output text)
DIST_ID=$(aws ssm get-parameter --name /seahaven-ap/deploy/distribution-id --query Parameter.Value --output text)
get_param() {
local name="$1" err value
err="$(mktemp)"
if ! value="$(aws ssm get-parameter --name "${name}" --query Parameter.Value --output text 2>"${err}")"; then
if grep -q ParameterNotFound "${err}"; then
echo "SSM parameter ${name} does not exist yet. Apply the seahaven-ap-dev workspace, then re-run this workflow." >&2
else
cat "${err}" >&2
fi
rm -f "${err}"
exit 1
fi
rm -f "${err}"
printf '%s\n' "${value}"
}
BUCKET=$(get_param /seahaven-ap/deploy/bucket)
DIST_ID=$(get_param /seahaven-ap/deploy/distribution-id)
DOMAIN=$(aws cloudfront get-distribution --id "${DIST_ID}" --query Distribution.DomainName --output text)
{
echo "bucket=${BUCKET}"

View file

@ -60,6 +60,8 @@ HCP Terraform workspace `seahaven-ap-dev` (project `seahaven-dev`) uses working
The first apply creates secret `seahaven-ap/google-oidc` with `client_id` and `client_secret` set to `replace-me`. Replace both values in Secrets Manager, then re-run the HCP apply. A `terraform/**` change on `main` starts that apply. The Google IdP is not registered while the placeholder is still current.
The merge that adds these workflows can start Deploy Web and Deploy API before that apply has written `/seahaven-ap/deploy/*` and before GitHub Environment `dev` has `DEPLOY_ROLE_ARN`. Those runs fail on purpose until both exist. Re-run them after the apply.
- `.github/workflows/deploy-web.yaml` syncs `placeholder/` to the web bucket. It does not run `vite build`.
- `.github/workflows/deploy-api.yaml` builds the API image with `GIT_SHA`, registers the task definition from `/seahaven-ap/deploy/task-environment`, migrates, and checks `GET /api/health`.

View file

@ -54,6 +54,7 @@ def test_no_hcp_iam_and_no_prod():
assert 'local.google_oidc_client_secret != "replace-me"' in cognito
readme = (ROOT / "README.md").read_text()
assert "Replace both values in Secrets Manager, then re-run the HCP apply." in readme
assert "Those runs fail on purpose until both exist." in readme
secrets = (tf_dir / "secrets.tf").read_text()
assert 'resource "aws_secretsmanager_secret_version" "google_oidc"' in secrets
assert "ignore_changes = [secret_string]" in secrets
@ -74,6 +75,8 @@ def test_deploy_workflows_are_dev_only():
assert "environment:prod" not in text
assert "cancel-in-progress: false" in text
assert "environment: ${{ needs.target.outputs.environment }}" in text
assert "DEPLOY_ROLE_ARN is empty" in text
assert "does not exist yet. Apply the seahaven-ap-dev workspace" in text
web = (ROOT / ".github" / "workflows" / "deploy-web.yaml").read_text()
assert "vite build" not in web
assert "placeholder/" in web