Add GitHub Actions deploy workflow #28

Merged
amoussa1229 merged 3 commits from feature/add-deploy-workflow into main 2026-05-08 21:08:12 +00:00
amoussa1229 commented 2026-05-08 20:51:36 +00:00 (Migrated from github.com)

Summary

Adds OIDC-based deploy workflow that triggers on push to main. Uses the org-level reusable cd-cdk.yaml workflow with CDK bootstrap role delegation.

Validation

  • IAM deploy role provisioned via github-oidc-deploy-roles CloudFormation stack
  • AWS_DEPLOY_ROLE_ARN secret set on this repo
  • Reusable workflow merged to .github repo

Tests

Deploy will be validated on first merge to main.

## Summary Adds OIDC-based deploy workflow that triggers on push to `main`. Uses the org-level reusable `cd-cdk.yaml` workflow with CDK bootstrap role delegation. ## Validation - IAM deploy role provisioned via `github-oidc-deploy-roles` CloudFormation stack - `AWS_DEPLOY_ROLE_ARN` secret set on this repo - Reusable workflow merged to `.github` repo ## Tests Deploy will be validated on first merge to `main`.
cursor[bot] commented 2026-05-08 20:51:42 +00:00 (Migrated from github.com)

PR Summary

Medium Risk
Introduces an automated deployment trigger on every push to main using OIDC role assumption; misconfiguration could cause failed or unintended deployments. No application runtime code is changed.

Overview
Adds a new GitHub Actions workflow, deploy.yaml, that triggers on pushes to main and runs a reusable org-level cd-cdk.yaml deployment job.

The workflow enables OIDC token permissions, sets a single deploy concurrency group (no cancel-in-progress), and passes AWS_DEPLOY_ROLE_ARN as the deploy-role-arn secret to the reusable workflow.

Reviewed by Cursor Bugbot for commit f4c23c494d. Bugbot is set up for automated code reviews on this repo. Configure here.

## PR Summary <!-- CURSOR_SUMMARY --> **Medium Risk** Introduces an automated deployment trigger on every push to `main` using OIDC role assumption; misconfiguration could cause failed or unintended deployments. No application runtime code is changed. **Overview** Adds a new GitHub Actions workflow, `deploy.yaml`, that triggers on pushes to `main` and runs a reusable org-level `cd-cdk.yaml` deployment job. The workflow enables OIDC token permissions, sets a single `deploy` concurrency group (no cancel-in-progress), and passes `AWS_DEPLOY_ROLE_ARN` as the `deploy-role-arn` secret to the reusable workflow. <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit f4c23c494d22f22f906939969ff5af97985b1e6c. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY -->
claude[bot] commented 2026-05-08 20:53:00 +00:00 (Migrated from github.com)

Looks good. Mirrors the existing ci.yaml pattern of delegating to the org-level reusable workflow, secret is passed correctly via the secrets block, and there's no hardcoded sensitive data. Nothing to flag.

Looks good. Mirrors the existing `ci.yaml` pattern of delegating to the org-level reusable workflow, secret is passed correctly via the `secrets` block, and there's no hardcoded sensitive data. Nothing to flag.
cursor[bot] (Migrated from github.com) reviewed 2026-05-08 20:53:09 +00:00
cursor[bot] (Migrated from github.com) left a comment

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 0302e6b021. Configure here.

<!-- BUGBOT_REVIEW --> Cursor Bugbot has reviewed your changes and found 1 potential issue. <!-- BUGBOT_FIX_ALL --> <a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9BTExfSU5fQ1VSU09SIiwiZGF0YSI6eyJyZWRpc0tleSI6ImJ1Z2JvdC1tdWx0aToyOTdhNmE0Zi1jMzU0LTRkOGQtYmYxNy1hNzhkMTdhNTM3ZTAiLCJlbmNyeXB0aW9uS2V5IjoiTXVTenVPSWRwWlkzbkJhYllMRXdjemxoSUFjb1NFTUZSOFFDYVM2TzB4RSIsImJyYW5jaCI6ImZlYXR1cmUvYWRkLWRlcGxveS13b3JrZmxvdyIsInJlcG9Pd25lciI6IlNlYS1IYXZlbi1JbmR1c3RyaWVzIiwicmVwb05hbWUiOiJzZWFoYXZlbi1zbGFjay1ib3QifSwiaWF0IjoxNzc4MjczNTg5LCJleHAiOjE3ODA4NjU1ODl9.ONYx1lMn5xLJZt3J-bLJ87acVP8aBdH1WhtDiODbGCCo6qQd8W2jxG6EVWoQJM_lkdgOk9NjuA_Lj0AeWH1pP3hQd9aPcosBIa9K4lRpIWLz0fqN8U_bMU98Va3OP6Biqk5-1ta-GPDpZ3twVaunfSAyIbWHXGfZl00N75LEYvmdILWA6t5KIkw1YyhZoAvuHiYFQ9C5xierLomG7CzcV1J1w-AMR99RxzTMB9TXPiV7_4jh1QKY7YyDra9D0cKZVrxriQJEE2gNsGtOtb9Bsn4NRW4EJugKWfLvnfKWu6zvUApNs5KS0qkIKtRQLgKyp-R67a4MppwIgDghoFpKpQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix All in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a> <!-- /BUGBOT_FIX_ALL --> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_BEGIN --> <sup>❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the [Cursor dashboard](https://www.cursor.com/dashboard/bugbot).</sup> <!-- BUGBOT_AUTOFIX_REVIEW_FOOTNOTE_END --> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 0302e6b021dcf0adf422cacdd33796e6f857ddbc. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
@ -0,0 +15,4 @@
deploy:
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
secrets:
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
cursor[bot] (Migrated from github.com) commented 2026-05-08 20:53:10 +00:00

Missing OIDC permission blocks deploy workflow

High Severity

This OIDC-based deploy workflow is missing the permissions block with id-token: write. GitHub Actions does not grant the id-token permission by default — it must be explicitly declared in the caller workflow. Without it, the reusable cd-cdk.yaml workflow cannot request the JWT needed to assume the AWS deploy role, and every deployment will fail.

Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 0302e6b021. Configure here.

### Missing OIDC permission blocks deploy workflow **High Severity** <!-- DESCRIPTION START --> This OIDC-based deploy workflow is missing the `permissions` block with `id-token: write`. GitHub Actions does not grant the `id-token` permission by default — it must be explicitly declared in the caller workflow. Without it, the reusable `cd-cdk.yaml` workflow cannot request the JWT needed to assume the AWS deploy role, and every deployment will fail. <!-- DESCRIPTION END --> <!-- BUGBOT_BUG_ID: 22b534b2-fd0e-47e1-b899-949cc5dfc4c6 --> <!-- LOCATIONS START .github/workflows/deploy.yaml#L1-L10 LOCATIONS END --> <div><a href="https://cursor.com/open?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9DVVJTT1IiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmUxYjJmOThlLTc3NGMtNDk0OS1iZmVmLTE0Yzc4MzUzNTM0YiIsImVuY3J5cHRpb25LZXkiOiJYcC02czY5V2o0bE1HSUJPS1RZT0JrR0h2RzlqUmFSWUFyeUo4TER0aDdnIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6InNlYWhhdmVuLXNsYWNrLWJvdCJ9LCJpYXQiOjE3NzgyNzM1ODksImV4cCI6MTc4MDg2NTU4OX0.WpkUj4gN9Ip1IkPbijittx9TDn3kFhNZnGrCWL-yQ_d5mpdLvLSxg56T2Aub1kuMaNvXZQ_U9D3neXRIEou-PsEz5kfGH0o5UeZmnDPSf6xxc_LRNb1-D_z-NLVqqhIQTSl-fS4S26XKwOHXFAR7tAzR5QfcoMldSiAKXh5tG5uYfV2aQyAOd3S68zQeaOdnUDKASDDNevl97Bh8Tlmro94czJoTYE2YZOnH0ZfpsIoaZ5eLmeZYuQbxW-dsZcPWu1TAqhldzQYbxe3BBq_wYuOB0Oujlx2MamgK3pfOzUeYgsydZrduzzYIxlLwrfy28S9NnIG7JWWilIrXn1XBLQ" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-cursor-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-cursor-light.png"><img alt="Fix in Cursor" width="115" height="28" src="https://cursor.com/assets/images/fix-in-cursor-dark.png"></picture></a>&nbsp;<a href="https://cursor.com/agents?data=eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6ImJ1Z2JvdC12MiJ9.eyJ2ZXJzaW9uIjoxLCJ0eXBlIjoiQlVHQk9UX0ZJWF9JTl9XRUIiLCJkYXRhIjp7InJlZGlzS2V5IjoiYnVnYm90OmUxYjJmOThlLTc3NGMtNDk0OS1iZmVmLTE0Yzc4MzUzNTM0YiIsImVuY3J5cHRpb25LZXkiOiJYcC02czY5V2o0bE1HSUJPS1RZT0JrR0h2RzlqUmFSWUFyeUo4TER0aDdnIiwiYnJhbmNoIjoiZmVhdHVyZS9hZGQtZGVwbG95LXdvcmtmbG93IiwicmVwb093bmVyIjoiU2VhLUhhdmVuLUluZHVzdHJpZXMiLCJyZXBvTmFtZSI6InNlYWhhdmVuLXNsYWNrLWJvdCIsInByTnVtYmVyIjoyOCwiY29tbWl0U2hhIjoiMDMwMmU2YjAyMWRjZjBhZGY0MjJjYWNkZDMzNzk2ZTZmODU3ZGRiYyIsInByb3ZpZGVyIjoiZ2l0aHViIn0sImlhdCI6MTc3ODI3MzU4OSwiZXhwIjoxNzgwODY1NTg5fQ.AB7KDJDiOVbKvW9Wy_nQ346hGn1Cuwe_C-7Pw_kiWQ2NxUnBDZijsM23odC9RMb4ZG_rCStl0L2lWcC6RCk6K14DddegkFyd5WNnjYXz81Su1bjnVaPSUD2GIf41vJBG14ZdKdIF6Znzzf1gJtq0ELqovZJ-Cdd_kIfo-tGOnxPesJHvKoKwWA1X-F6OSfELSSysY1cHU-2iY65u-K8rEZMh0HR5sdVQEBwSC8NwOB1l8afd54Y8ubTBR3MyANRopi1VYfMP14QF_AC6MRd-x8q9M0N9n6XRHiIjmafJjXTd0NEv5LkxrvzliiqOR2alx9l4EA-MV9UnbZRm1_9Pxg" target="_blank" rel="noopener noreferrer"><picture><source media="(prefers-color-scheme: dark)" srcset="https://cursor.com/assets/images/fix-in-web-dark.png"><source media="(prefers-color-scheme: light)" srcset="https://cursor.com/assets/images/fix-in-web-light.png"><img alt="Fix in Web" width="99" height="28" src="https://cursor.com/assets/images/fix-in-web-dark.png"></picture></a></div> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 0302e6b021dcf0adf422cacdd33796e6f857ddbc. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup>
claude[bot] commented 2026-05-08 20:57:34 +00:00 (Migrated from github.com)

LGTM. Workflow follows the same reusable-workflow pattern as ci.yaml, OIDC permissions are correctly scoped (id-token: write, contents: read), and the deploy role ARN is sourced from a repo secret. No issues found.

LGTM. Workflow follows the same reusable-workflow pattern as ci.yaml, OIDC permissions are correctly scoped (id-token: write, contents: read), and the deploy role ARN is sourced from a repo secret. No issues found.
claude[bot] commented 2026-05-08 21:03:04 +00:00 (Migrated from github.com)

Reviewed — looks good. OIDC permissions are scoped correctly (id-token: write, contents: read), AWS_DEPLOY_ROLE_ARN is sourced from secrets, and concurrency.cancel-in-progress: false is the right choice for deploys to avoid mid-flight cancellations. Pattern matches the existing ci.yaml reference to the org-level reusable workflow.

Reviewed — looks good. OIDC permissions are scoped correctly (`id-token: write`, `contents: read`), `AWS_DEPLOY_ROLE_ARN` is sourced from secrets, and `concurrency.cancel-in-progress: false` is the right choice for deploys to avoid mid-flight cancellations. Pattern matches the existing `ci.yaml` reference to the org-level reusable workflow.
This repo is archived. You cannot comment on pull requests.
No description provided.