seahaven-site/.github/workflows/deploy.yaml
dependabot[bot] 76365ceeeb
Some checks failed
Deploy / deploy (push) Has been cancelled
Bump actions/checkout from 6 to 7 (#22)
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-06-26 12:29:43 -04:00

77 lines
2.6 KiB
YAML

name: Deploy
on:
push:
branches:
- main
permissions:
id-token: write # Required for OIDC
contents: read # Allows checkout of repo
# Never cancel a deploy mid-flight: cancelling between the S3 sync and the
# CloudFront invalidation (or mid `--delete`) would leave the bucket in a
# half-updated state. Queue instead.
concurrency:
group: deploy-${{ github.ref }}
cancel-in-progress: false
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v7
- name: Set up Node
uses: actions/setup-node@v6
with:
node-version: "24"
cache: npm
- name: Build site
run: |
npm ci --ignore-scripts
npm run build
# Fail closed: never let a silently-empty build reach the --delete sync.
test -f _site/index.html
test -f _site/contact/index.html
test -f _site/404.html
count=$(find _site -type f | wc -l)
if [ "$count" -lt 40 ]; then
echo "::error::build produced only $count files (expected >= 40); aborting deploy"
exit 1
fi
echo "Build OK: $count files."
- name: Configure AWS credentials using OIDC
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: arn:aws:iam::328440206208:role/githubdeploy_seahavensite
aws-region: us-east-1
- name: Sync build output to S3
run: |
# 1) Static assets — 1-day browser cache (no filename fingerprinting yet,
# so do NOT go immutable). CloudFront /* invalidation below keeps the
# edge fresh; this only affects returning visitors' browser cache.
aws s3 sync _site/ s3://seahaven.com --no-progress \
--exclude "*.html" --exclude "*.xml" --exclude "*.txt" \
--cache-control "public, max-age=86400"
# 2) HTML / sitemap / robots — always revalidate so a deploy is seen immediately.
aws s3 sync _site/ s3://seahaven.com --no-progress \
--exclude "*" --include "*.html" --include "*.xml" --include "*.txt" \
--cache-control "no-cache"
# 3) Prune files removed from the build. This pass sets no metadata, so
# it skips already-uploaded objects (preserving the Cache-Control set
# above) and only deletes objects no longer present in _site/.
aws s3 sync _site/ s3://seahaven.com --no-progress --delete
- name: Invalidate CloudFront cache
run: |
aws cloudfront create-invalidation \
--distribution-id EYK41AG0PO6XU \
--paths "/*"