seahaven-org-baseline/.github/workflows/deploy.yaml
Adam Moussa 5b63c703bc
feat(iam): move seahaven-site exec roles into their own stack (PLAT-225)
Drop the retained roles from the substrate template so the new stack can import them without a second owner.
2026-09-24 17:51:17 -04:00

65 lines
2.5 KiB
YAML

name: Deploy
on:
push:
branches: [main]
permissions:
id-token: write
contents: read
concurrency:
group: deploy
cancel-in-progress: false
# One job per target AWS account: cdk deploy with explicit stack selectors so
# each OIDC role only ever deploys its own account's stacks. A new stack added
# to bin/app.ts MUST be appended to exactly one job's `stacks` list — explicit
# selectors mean an unlisted stack is silently never deployed (security review
# SH-ORG-005).
jobs:
deploy-management:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
stacks: "account-baseline dynamodb-cmk regional-baseline-us-west-2 regional-baseline-us-east-2 backup-offsite backup org-governance"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
deploy-external-dev:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
stacks: "external-dev-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_EXTDEV }}
deploy-security:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
stacks: "security-baseline"
stack-name: "seahaven-security-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_SECURITY }}
deploy-dev:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
stacks: "dev-baseline deploy-substrate-dev terraform-substrate-dev"
stack-name: "seahaven-dev-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_DEV }}
deploy-prod:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@e5691d8a7f96ac4d5a841a82975ff0a4354d53ac # v1.0.7
with:
node-version: "24"
# seahaven-site-hcptf stays off this list until `cdk import` adopts the
# live roles. A create fails, and a failed create blocks the import.
# Add the id here in the change that follows a successful import.
stacks: "prod-baseline dynamodb-cmk-prod alarm-topic-prod deploy-substrate-prod terraform-substrate-prod app-web-acl-prod"
stack-name: "seahaven-prod-baseline"
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN_PROD }}