Compare commits

..

3 commits

6 changed files with 35 additions and 41 deletions

View file

@ -5,7 +5,9 @@ name: Deploy API
# and ignores container_definitions / task_definition.
#
# push to main -> GitHub Environment dev, at github.sha
# workflow_dispatch -> GitHub Environment dev at a chosen ref
# workflow_dispatch -> GitHub Environment dev. The workflow file must be main.
# inputs.ref is only the image source. Deploy scripts stay
# on github.sha, which is the trusted workflow commit.
#
# Cluster, service, ECR, and task env come from SSM after assuming the
# Environment's DEPLOY_ROLE_ARN. Terraform owns /seahaven-ap/deploy/task-environment;
@ -68,6 +70,10 @@ jobs:
ref="${GITHUB_SHA_IN}"
;;
workflow_dispatch)
if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then
echo "workflow_dispatch deploys only run from main" >&2
exit 1
fi
environment="${INPUT_ENVIRONMENT:-dev}"
if [ "${environment}" != "dev" ]; then
echo "only GitHub Environment dev is allowed" >&2
@ -102,13 +108,23 @@ jobs:
AWS_REGION: us-east-1
DEPLOY_ROLE_ARN: ${{ vars.DEPLOY_ROLE_ARN }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Checkout trusted workflow
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.sha }}
persist-credentials: false
path: ci
- name: Checkout image source
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ needs.target.outputs.ref }}
persist-credentials: false
path: src
- name: Resolve commit
id: commit
working-directory: src
run: |
set -euo pipefail
sha="$(git rev-parse HEAD)"
@ -153,6 +169,7 @@ jobs:
ECR: ${{ steps.deploy.outputs.ecr }}
GIT_SHA: ${{ steps.commit.outputs.sha }}
ENVIRONMENT: ${{ needs.target.outputs.environment }}
working-directory: src
run: |
set -euo pipefail
docker build \
@ -192,7 +209,7 @@ jobs:
--task-definition "${FAMILY}" \
--query taskDefinition \
--output json \
| python3 scripts/patch-ecs-task-def.py > /tmp/task-def.json
| python3 "${GITHUB_WORKSPACE}/ci/scripts/patch-ecs-task-def.py" > /tmp/task-def.json
REV="$(aws ecs register-task-definition --cli-input-json file:///tmp/task-def.json --query taskDefinition.revision --output text)"
NET="$(aws ecs describe-services --cluster "${CLUSTER}" --services "${SERVICE}" \
--query 'services[0].networkConfiguration.awsvpcConfiguration' --output json)"
@ -225,4 +242,4 @@ jobs:
env:
SITE_URL: ${{ steps.deploy.outputs.site_url }}
EXPECTED_SHA: ${{ steps.commit.outputs.sha }}
run: bash scripts/verify-api-health.sh
run: bash "${GITHUB_WORKSPACE}/ci/scripts/verify-api-health.sh"

View file

@ -5,7 +5,9 @@ name: Deploy Web
# distribution and never touches content. Do not run a SPA production build.
#
# push to main -> GitHub Environment dev, at github.sha
# workflow_dispatch -> GitHub Environment dev at a chosen ref
# workflow_dispatch -> GitHub Environment dev. The workflow file must be main.
# inputs.ref selects the placeholder tree to publish.
# Job steps are the workflow file, not scripts from that ref.
#
# Nothing here creates an HCP run. Prod is AP-12.
@ -70,6 +72,10 @@ jobs:
ref="${GITHUB_SHA_IN}"
;;
workflow_dispatch)
if [ "${GITHUB_REF_NAME_IN}" != "refs/heads/main" ]; then
echo "workflow_dispatch deploys only run from main" >&2
exit 1
fi
environment="${INPUT_ENVIRONMENT:-dev}"
if [ "${environment}" != "dev" ]; then
echo "only GitHub Environment dev is allowed" >&2

View file

@ -1,5 +1,9 @@
# This file instructs Redocly's linter to ignore the rules contained for specific parts of your API.
# See https://redocly.com/docs/cli/ for more information.
#
# Intentionally empty for AP-14 foundation. Add justified ignores in the same
# style as Sea-Haven-Industries/procurement-ingest when needed.
# Login and callback fail with a 302 redirect, or 500 when Cognito is not configured.
packages/api/openapi/paths/auth-login.yaml:
operation-4xx-response:
- '#/get/responses'
packages/api/openapi/paths/auth-callback.yaml:
operation-4xx-response:
- '#/get/responses'

View file

@ -30,14 +30,3 @@ get:
responses:
"302":
description: Redirect to the SPA or the login error page.
"400":
description: Bad request.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
example:
error:
code: VALIDATION_ERROR
message: Bad request.
correlationId: 11111111-1111-4111-8111-111111111111

View file

@ -17,17 +17,6 @@ get:
responses:
"302":
description: Redirect to Cognito hosted UI.
"400":
description: Bad request.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
example:
error:
code: VALIDATION_ERROR
message: Bad request.
correlationId: 11111111-1111-4111-8111-111111111111
"500":
description: Cognito is not configured.
content:

View file

@ -19,14 +19,3 @@ post:
code: FORBIDDEN
message: Origin is not allowed.
correlationId: 11111111-1111-4111-8111-111111111111
"400":
description: Bad request.
content:
application/json:
schema:
$ref: ../components/schemas.yaml#/Error
example:
error:
code: VALIDATION_ERROR
message: Bad request.
correlationId: 11111111-1111-4111-8111-111111111111