feat(ci): retarget content deploy to seahaven-prod origin

Point OIDC, S3 sync, and CloudFront invalidation at the HCP-managed
prod hosting stack so GHA remains the content publish path after cutover.
This commit is contained in:
Adam Moussa 2026-08-07 14:33:24 -04:00
parent 09854fcf7c
commit b418d183eb

View file

@ -48,7 +48,7 @@ jobs:
- name: Configure AWS credentials using OIDC
uses: aws-actions/configure-aws-credentials@e6de054238d6b7531b4efff3b6587d9aade6a06c # v6
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy_seahavensite
role-to-assume: arn:aws:iam::011934824531:role/tf-managed/githubdeploy-seahaven-site
aws-region: us-east-1
- name: Sync build output to S3
@ -56,22 +56,22 @@ jobs:
# 1) Static assets — 1-day browser cache (no filename fingerprinting yet,
# so do NOT go immutable). CloudFront /* invalidation below keeps the
# edge fresh; this only affects returning visitors' browser cache.
aws s3 sync _site/ s3://seahaven.com --no-progress \
aws s3 sync _site/ s3://seahaven-site-prod --no-progress \
--exclude "*.html" --exclude "*.xml" --exclude "*.txt" \
--cache-control "public, max-age=86400"
# 2) HTML / sitemap / robots — always revalidate so a deploy is seen immediately.
aws s3 sync _site/ s3://seahaven.com --no-progress \
aws s3 sync _site/ s3://seahaven-site-prod --no-progress \
--exclude "*" --include "*.html" --include "*.xml" --include "*.txt" \
--cache-control "no-cache"
# 3) Prune files removed from the build. This pass sets no metadata, so
# it skips already-uploaded objects (preserving the Cache-Control set
# above) and only deletes objects no longer present in _site/.
aws s3 sync _site/ s3://seahaven.com --no-progress --delete
aws s3 sync _site/ s3://seahaven-site-prod --no-progress --delete
- name: Invalidate CloudFront cache
run: |
aws cloudfront create-invalidation \
--distribution-id EYK41AG0PO6XU \
--distribution-id E35OCA79OAJ03H \
--paths "/*"