name: Deploy on: push: branches: - main permissions: id-token: write # Required for OIDC contents: read # Allows checkout of repo # Never cancel a deploy mid-flight: cancelling between the S3 sync and the # CloudFront invalidation (or mid `--delete`) would leave the bucket in a # half-updated state. Queue instead. concurrency: group: deploy-${{ github.ref }} cancel-in-progress: false jobs: deploy: runs-on: ubuntu-latest steps: - name: Checkout repository uses: actions/checkout@v7 - name: Set up Node uses: actions/setup-node@v7 with: node-version: "24" cache: npm - name: Build site run: | npm ci --ignore-scripts npm run build # Fail closed: never let a silently-empty build reach the --delete sync. test -f _site/index.html test -f _site/contact/index.html test -f _site/404.html count=$(find _site -type f | wc -l) if [ "$count" -lt 40 ]; then echo "::error::build produced only $count files (expected >= 40); aborting deploy" exit 1 fi echo "Build OK: $count files." - name: Configure AWS credentials using OIDC uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6 with: role-to-assume: arn:aws:iam::328440206208:role/githubdeploy_seahavensite aws-region: us-east-1 - name: Sync build output to S3 run: | # 1) Static assets — 1-day browser cache (no filename fingerprinting yet, # so do NOT go immutable). CloudFront /* invalidation below keeps the # edge fresh; this only affects returning visitors' browser cache. aws s3 sync _site/ s3://seahaven.com --no-progress \ --exclude "*.html" --exclude "*.xml" --exclude "*.txt" \ --cache-control "public, max-age=86400" # 2) HTML / sitemap / robots — always revalidate so a deploy is seen immediately. aws s3 sync _site/ s3://seahaven.com --no-progress \ --exclude "*" --include "*.html" --include "*.xml" --include "*.txt" \ --cache-control "no-cache" # 3) Prune files removed from the build. This pass sets no metadata, so # it skips already-uploaded objects (preserving the Cache-Control set # above) and only deletes objects no longer present in _site/. aws s3 sync _site/ s3://seahaven.com --no-progress --delete - name: Invalidate CloudFront cache run: | aws cloudfront create-invalidation \ --distribution-id EYK41AG0PO6XU \ --paths "/*"