Add GitHub Actions deploy workflow #28
No reviewers
Labels
No labels
app
bug
ci
compliance
dependencies
docker
docs
documentation
duplicate
enhancement
good first issue
help wanted
infra
invalid
javascript
question
wontfix
No milestone
No project
No assignees
1 participant
Due date
No due date set.
Dependencies
No dependencies set.
Reference: adam/seahaven-slack-bot#28
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feature/add-deploy-workflow"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Adds OIDC-based deploy workflow that triggers on push to
main. Uses the org-level reusablecd-cdk.yamlworkflow with CDK bootstrap role delegation.Validation
github-oidc-deploy-rolesCloudFormation stackAWS_DEPLOY_ROLE_ARNsecret set on this repo.githubrepoTests
Deploy will be validated on first merge to
main.PR Summary
Medium Risk
Introduces an automated deployment trigger on every push to
mainusing OIDC role assumption; misconfiguration could cause failed or unintended deployments. No application runtime code is changed.Overview
Adds a new GitHub Actions workflow,
deploy.yaml, that triggers on pushes tomainand runs a reusable org-levelcd-cdk.yamldeployment job.The workflow enables OIDC token permissions, sets a single
deployconcurrency group (no cancel-in-progress), and passesAWS_DEPLOY_ROLE_ARNas thedeploy-role-arnsecret to the reusable workflow.Reviewed by Cursor Bugbot for commit
f4c23c494d. Bugbot is set up for automated code reviews on this repo. Configure here.Looks good. Mirrors the existing
ci.yamlpattern of delegating to the org-level reusable workflow, secret is passed correctly via thesecretsblock, and there's no hardcoded sensitive data. Nothing to flag.Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit
0302e6b021. Configure here.@ -0,0 +15,4 @@deploy:uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@mainsecrets:deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}Missing OIDC permission blocks deploy workflow
High Severity
This OIDC-based deploy workflow is missing the
permissionsblock withid-token: write. GitHub Actions does not grant theid-tokenpermission by default — it must be explicitly declared in the caller workflow. Without it, the reusablecd-cdk.yamlworkflow cannot request the JWT needed to assume the AWS deploy role, and every deployment will fail.Reviewed by Cursor Bugbot for commit
0302e6b021. Configure here.LGTM. Workflow follows the same reusable-workflow pattern as ci.yaml, OIDC permissions are correctly scoped (id-token: write, contents: read), and the deploy role ARN is sourced from a repo secret. No issues found.
Reviewed — looks good. OIDC permissions are scoped correctly (
id-token: write,contents: read),AWS_DEPLOY_ROLE_ARNis sourced from secrets, andconcurrency.cancel-in-progress: falseis the right choice for deploys to avoid mid-flight cancellations. Pattern matches the existingci.yamlreference to the org-level reusable workflow.