mirror of
https://github.com/Sea-Haven-Industries/seahaven-ap.git
synced 2026-10-07 06:58:53 +00:00
Compare commits
1 commit
1e6d86d479
...
756eda21d6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
756eda21d6 |
6 changed files with 41 additions and 35 deletions
25
.github/workflows/deploy-api.yaml
vendored
25
.github/workflows/deploy-api.yaml
vendored
|
|
@ -5,9 +5,7 @@ name: Deploy API
|
|||
# and ignores container_definitions / task_definition.
|
||||
#
|
||||
# push to main -> GitHub Environment dev, at github.sha
|
||||
# workflow_dispatch -> GitHub Environment dev. The workflow file must be main.
|
||||
# inputs.ref is only the image source. Deploy scripts stay
|
||||
# on github.sha, which is the trusted workflow commit.
|
||||
# workflow_dispatch -> GitHub Environment dev at a chosen ref
|
||||
#
|
||||
# Cluster, service, ECR, and task env come from SSM after assuming the
|
||||
# Environment's DEPLOY_ROLE_ARN. Terraform owns /seahaven-ap/deploy/task-environment;
|
||||
|
|
@ -70,10 +68,6 @@ jobs:
|
|||
ref="${GITHUB_SHA_IN}"
|
||||
;;
|
||||
workflow_dispatch)
|
||||
if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then
|
||||
echo "workflow_dispatch deploys only run from main" >&2
|
||||
exit 1
|
||||
fi
|
||||
environment="${INPUT_ENVIRONMENT:-dev}"
|
||||
if [ "${environment}" != "dev" ]; then
|
||||
echo "only GitHub Environment dev is allowed" >&2
|
||||
|
|
@ -108,23 +102,13 @@ jobs:
|
|||
AWS_REGION: us-east-1
|
||||
DEPLOY_ROLE_ARN: ${{ vars.DEPLOY_ROLE_ARN }}
|
||||
steps:
|
||||
- name: Checkout trusted workflow
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
ref: ${{ github.sha }}
|
||||
persist-credentials: false
|
||||
path: ci
|
||||
|
||||
- name: Checkout image source
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
ref: ${{ needs.target.outputs.ref }}
|
||||
persist-credentials: false
|
||||
path: src
|
||||
|
||||
- name: Resolve commit
|
||||
id: commit
|
||||
working-directory: src
|
||||
run: |
|
||||
set -euo pipefail
|
||||
sha="$(git rev-parse HEAD)"
|
||||
|
|
@ -169,7 +153,6 @@ jobs:
|
|||
ECR: ${{ steps.deploy.outputs.ecr }}
|
||||
GIT_SHA: ${{ steps.commit.outputs.sha }}
|
||||
ENVIRONMENT: ${{ needs.target.outputs.environment }}
|
||||
working-directory: src
|
||||
run: |
|
||||
set -euo pipefail
|
||||
docker build \
|
||||
|
|
@ -209,7 +192,7 @@ jobs:
|
|||
--task-definition "${FAMILY}" \
|
||||
--query taskDefinition \
|
||||
--output json \
|
||||
| python3 "${GITHUB_WORKSPACE}/ci/scripts/patch-ecs-task-def.py" > /tmp/task-def.json
|
||||
| python3 scripts/patch-ecs-task-def.py > /tmp/task-def.json
|
||||
REV="$(aws ecs register-task-definition --cli-input-json file:///tmp/task-def.json --query taskDefinition.revision --output text)"
|
||||
NET="$(aws ecs describe-services --cluster "${CLUSTER}" --services "${SERVICE}" \
|
||||
--query 'services[0].networkConfiguration.awsvpcConfiguration' --output json)"
|
||||
|
|
@ -242,4 +225,4 @@ jobs:
|
|||
env:
|
||||
SITE_URL: ${{ steps.deploy.outputs.site_url }}
|
||||
EXPECTED_SHA: ${{ steps.commit.outputs.sha }}
|
||||
run: bash "${GITHUB_WORKSPACE}/ci/scripts/verify-api-health.sh"
|
||||
run: bash scripts/verify-api-health.sh
|
||||
|
|
|
|||
8
.github/workflows/deploy-web.yaml
vendored
8
.github/workflows/deploy-web.yaml
vendored
|
|
@ -5,9 +5,7 @@ name: Deploy Web
|
|||
# distribution and never touches content. Do not run a SPA production build.
|
||||
#
|
||||
# push to main -> GitHub Environment dev, at github.sha
|
||||
# workflow_dispatch -> GitHub Environment dev. The workflow file must be main.
|
||||
# inputs.ref selects the placeholder tree to publish.
|
||||
# Job steps are the workflow file, not scripts from that ref.
|
||||
# workflow_dispatch -> GitHub Environment dev at a chosen ref
|
||||
#
|
||||
# Nothing here creates an HCP run. Prod is AP-12.
|
||||
|
||||
|
|
@ -72,10 +70,6 @@ jobs:
|
|||
ref="${GITHUB_SHA_IN}"
|
||||
;;
|
||||
workflow_dispatch)
|
||||
if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then
|
||||
echo "workflow_dispatch deploys only run from main" >&2
|
||||
exit 1
|
||||
fi
|
||||
environment="${INPUT_ENVIRONMENT:-dev}"
|
||||
if [ "${environment}" != "dev" ]; then
|
||||
echo "only GitHub Environment dev is allowed" >&2
|
||||
|
|
|
|||
|
|
@ -1,9 +1,5 @@
|
|||
# This file instructs Redocly's linter to ignore the rules contained for specific parts of your API.
|
||||
# See https://redocly.com/docs/cli/ for more information.
|
||||
# Login and callback fail with a 302 redirect, or 500 when Cognito is not configured.
|
||||
packages/api/openapi/paths/auth-login.yaml:
|
||||
operation-4xx-response:
|
||||
- '#/get/responses'
|
||||
packages/api/openapi/paths/auth-callback.yaml:
|
||||
operation-4xx-response:
|
||||
- '#/get/responses'
|
||||
#
|
||||
# Intentionally empty for AP-14 foundation. Add justified ignores in the same
|
||||
# style as Sea-Haven-Industries/procurement-ingest when needed.
|
||||
|
|
|
|||
|
|
@ -30,3 +30,14 @@ get:
|
|||
responses:
|
||||
"302":
|
||||
description: Redirect to the SPA or the login error page.
|
||||
"400":
|
||||
description: Bad request.
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: ../components/schemas.yaml#/Error
|
||||
example:
|
||||
error:
|
||||
code: VALIDATION_ERROR
|
||||
message: Bad request.
|
||||
correlationId: 11111111-1111-4111-8111-111111111111
|
||||
|
|
|
|||
|
|
@ -17,6 +17,17 @@ get:
|
|||
responses:
|
||||
"302":
|
||||
description: Redirect to Cognito hosted UI.
|
||||
"400":
|
||||
description: Bad request.
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: ../components/schemas.yaml#/Error
|
||||
example:
|
||||
error:
|
||||
code: VALIDATION_ERROR
|
||||
message: Bad request.
|
||||
correlationId: 11111111-1111-4111-8111-111111111111
|
||||
"500":
|
||||
description: Cognito is not configured.
|
||||
content:
|
||||
|
|
|
|||
|
|
@ -19,3 +19,14 @@ post:
|
|||
code: FORBIDDEN
|
||||
message: Origin is not allowed.
|
||||
correlationId: 11111111-1111-4111-8111-111111111111
|
||||
"400":
|
||||
description: Bad request.
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: ../components/schemas.yaml#/Error
|
||||
example:
|
||||
error:
|
||||
code: VALIDATION_ERROR
|
||||
message: Bad request.
|
||||
correlationId: 11111111-1111-4111-8111-111111111111
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue