name: Deploy # Static-site CD. The org reusable builds _site/, syncs the bucket root, and # invalidates CloudFront. Terraform owns the bucket and the distribution. # Nothing here creates an HCP run. # # push to main -> prod # weekday cron -> prod (Paychex listings, no commit) # workflow_dispatch -> prod, the main commit only # # Vercel previews branches other than main. on: push: branches: [main] paths-ignore: # deploy.yaml is included so this transition commit does not start a # prod deploy before the exec role can write the SSM contract. - "terraform/**" - "**/*.md" - ".github/workflows/ci.yaml" - ".github/workflows/deploy.yaml" - ".github/workflows/labeler.yml" - ".github/workflows/dependency-review.yml" schedule: # Weekday morning US Eastern (13:00 UTC). Rebuilds listings from Paychex # without a commit. A failed feed fetch aborts before the S3 sync. - cron: "0 13 * * 1-5" workflow_dispatch: permissions: contents: read jobs: deploy-prod: name: Deploy site to prod uses: Sea-Haven-Industries/.github/.github/workflows/cd-hcp-static.yaml@0a1010e63248c9ca9f042c870eb2c579ba6b9455 # v1.0.19 permissions: contents: read id-token: write secrets: inherit with: environment: prod ssm-prefix: /seahaven-site/deploy output-dir: _site required-paths: _site/index.html,_site/contact/index.html,_site/404.html min-file-count: 40 ship-gate: true